CVE-2011-3626
27.01.2012, 15:55
Double free vulnerability in the prepare_exec function in src/exec.c in Logsurfer 1.5b and earlier, and Logsurfer+ 1.7 and earlier, allows remote attackers to execute arbitrary commands via crafted strings in a log file.Enginsight
Vendor | Product | Version |
---|---|---|
drusus | logsurfer | 𝑥 ≤ 1.5b |
drusus | logsurfer | 1.1 |
drusus | logsurfer | 1.2 |
drusus | logsurfer | 1.3 |
drusus | logsurfer | 1.4 |
drusus | logsurfer | 1.5 |
drusus | logsurfer | 1.5:beta |
drusus | logsurfer | 1.5:beta2 |
drusus | logsurfer | 1.5a:a |
drusus | logsurfer | 1.41 |
kerry_thompson | logsurfer\+ | 𝑥 ≤ 1.7 |
kerry_thompson | logsurfer\+ | 1.5a:a |
kerry_thompson | logsurfer\+ | 1.5b:b |
kerry_thompson | logsurfer\+ | 1.6 |
kerry_thompson | logsurfer\+ | 1.6a:a |
kerry_thompson | logsurfer\+ | 1.6b:b |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References