Description
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the logrotate configuration for openSUSE mailman3 package allows the mailman user to sent SIGHUP to arbitrary processes. This issue affects openSUSE Tumbleweed: from ? before 3.3.10-2.1.
Problem types
CWE-807: Reliance on Untrusted Inputs in a Security Decision
Product status
? (custom) before 3.3.10-2.1
Credits
Matthias Gerstner of SUSE
References
bugzilla.suse.com/show_bug.cgi?id=CVE-2025-53882