Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-1154

Опубликовано: 30 мар. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.9

Описание

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

РелизСтатусПримечание
dapper

not-affected

code not present
devel

released

3.7.8-6ubuntu4
hardy

not-affected

code not present
karmic

ignored

end of life
lucid

released

3.7.8-4ubuntu2.2
maverick

released

3.7.8-6ubuntu1.1
natty

released

3.7.8-6ubuntu3.1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 20%
0.00062
Низкий

6.9 Medium

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

nvd
около 14 лет назад

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

debian
около 14 лет назад

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier ...

github
около 3 лет назад

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

oracle-oval
около 14 лет назад

ELSA-2011-0407: logrotate security update (MODERATE)

EPSS

Процентиль: 20%
0.00062
Низкий

6.9 Medium

CVSS2

Уязвимость CVE-2011-1154