PT-2011-1052 · Krzyszto+1 · Logwatch+1

Jan Lieskovsky

·

Published

2011-02-25

·

Updated

2024-06-15

·

CVE-2011-1018

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions logwatch versions 7.3 through 7.3.6 logwatch versions prior to 7.4.0
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of the issue can be carried out remotely.
Recommendations For logwatch versions 7.3 through 7.3.6, update to version 7.4.0 or later. For logwatch versions prior to 7.4.0, update to version 7.4.0 or later. As a temporary workaround, consider restricting access to the logwatch package to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03317
BDU:2015-07417
BDU:2015-07418
BDU:2015-08716
BDU:2015-08717
BDU:2015-09435
CVE-2011-1018
DSA-2182-1
OPENSUSE-SU-2024:10097-1
RHSA-2011:0324
RHSA-2011_0324

Affected Products

Red Hat
Logwatch