CVE-2011-1018
logwatch - remote code execution
EPSS 18.3%
Description
logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.
How to fix CVE-2011-1018
To remediate CVE-2011-1018, upgrade the affected package to a fixed version below.
- Debian/logwatch—upgrade to 7.3.6.cvs20090906-2 or later
- Debian/logwatch—upgrade to 7.3.6.cvs20080702-2lenny1 or later
Is CVE-2011-1018 being exploited?
Moderate — EPSS is 18.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 7.3.6.cvs20090906-2
- from 0, < 7.3.6.cvs20080702-2lenny1