LWN.net Logo

logwatch: privilege escalation/arbitrary code execution

Package(s):logwatch CVE #(s):CVE-2011-1018
Created:March 1, 2011 Updated:March 28, 2012
Description: From the Ubuntu advisory:

Dominik George discovered that logwatch did not properly sanitize log file names that were passed to the shell as part of a command. If a remote attacker were able to generate specially crafted filenames (for example, via Samba logging), they could execute arbitrary code with root privileges.

Alerts:
CentOS CESA-2011:0324 2011-04-14
SUSE SUSE-SR:2011:005 2011-04-01
openSUSE openSUSE-SU-2011:0242-1 2011-03-30
Fedora FEDORA-2011-2318 2011-03-01
Fedora FEDORA-2011-2328 2011-03-01
Red Hat RHSA-2011:0324-01 2011-03-07
Ubuntu USN-1078-1 2011-03-01
Gentoo 201203-20 2012-03-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds