PT-2011-1052 · Krzyszto+1 · Logwatch+1

Jan Lieskovsky

·

Publicado

2011-02-25

·

Atualizado

2024-06-15

·

CVE-2011-1018

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions logwatch versions 7.3 through 7.3.6 logwatch versions prior to 7.4.0
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of the issue can be carried out remotely.
Recommendations For logwatch versions 7.3 through 7.3.6, update to version 7.4.0 or later. For logwatch versions prior to 7.4.0, update to version 7.4.0 or later. As a temporary workaround, consider restricting access to the logwatch package to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03317
BDU:2015-07417
BDU:2015-07418
BDU:2015-08716
BDU:2015-08717
BDU:2015-09435
CVE-2011-1018
DSA-2182-1
OPENSUSE-SU-2024:10097-1
RHSA-2011:0324
RHSA-2011_0324

Produtos afetados

Red Hat
Logwatch