|
|
| |
|
| |
logwatch: privilege escalation/arbitrary code execution
| Package(s): | logwatch |
CVE #(s): | CVE-2011-1018
|
| Created: | March 1, 2011 |
Updated: | March 28, 2012 |
| Description: |
From the Ubuntu advisory:
Dominik George discovered that logwatch did not properly sanitize
log file names that were passed to the shell as part of a command.
If a remote attacker were able to generate specially crafted filenames
(for example, via Samba logging), they could execute arbitrary code
with root privileges.
|
| Alerts: |
|
( Log in to post comments)
|
|
|