CVE-2011-1018

logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.
Severity
UNKNOWN
AV:N/AC:L/Au:N/C:C/I:C/A:C
Atk. Vector
NETWORK
Atk. Complexity
LOW
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
VendorProductVersion
logwatchlogwatch
7.3.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
logwatch
bullseye
7.5.5-1
fixed
sid
7.7-1
fixed
trixie
7.7-1
fixed
bookworm
7.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
logwatch
maverick
Fixed 7.3.6.cvs20090906-1ubuntu3.1
released
lucid
Fixed 7.3.6.cvs20090906-1ubuntu2.1
released
karmic
Fixed 7.3.6.cvs20090906-1ubuntu1.1
released
hardy
Fixed 7.3.6-1ubuntu1.1
released
dapper
Fixed 7.1-2ubuntu0.1
released
References