Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-1018

Опубликовано: 16 фев. 2011
Источник: redhat
CVSS2: 7.9

Описание

logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4logwatchNot affected
Red Hat Enterprise Linux 5logwatchFixedRHSA-2011:032407.03.2011
Red Hat Enterprise Linux 6logwatchFixedRHSA-2011:032407.03.2011

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-73->CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=680237logwatch: Privilege escalation due improper sanitization of special characters in log file names

7.9 High

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.

nvd
больше 14 лет назад

logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.

debian
больше 14 лет назад

logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbit ...

github
около 3 лет назад

logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.

oracle-oval
больше 14 лет назад

ELSA-2011-0324: logwatch security update (IMPORTANT)

7.9 High

CVSS2