Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-57xq-cfp9-365f

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

Ссылки

EPSS

Процентиль: 20%
0.00062
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 14 лет назад

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

redhat
больше 14 лет назад

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

nvd
около 14 лет назад

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

debian
около 14 лет назад

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier ...

oracle-oval
около 14 лет назад

ELSA-2011-0407: logrotate security update (MODERATE)

EPSS

Процентиль: 20%
0.00062
Низкий

Дефекты

CWE-20