Описание
logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 4 | logwatch | Not affected | ||
Red Hat Enterprise Linux 5 | logwatch | Fixed | RHSA-2011:0324 | 07.03.2011 |
Red Hat Enterprise Linux 6 | logwatch | Fixed | RHSA-2011:0324 | 07.03.2011 |
Показывать по
Дополнительная информация
Статус:
7.9 High
CVSS2
Связанные уязвимости
logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.
logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.
logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbit ...
logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.
7.9 High
CVSS2