6.9

CVE-2011-1154

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GentooLogrotate Version <= 3.7.9
GentooLogrotate Version3.3 Updater2
GentooLogrotate Version3.5.9
GentooLogrotate Version3.5.9 Updater1
GentooLogrotate Version3.6.5
GentooLogrotate Version3.6.5 Updater1
GentooLogrotate Version3.7
GentooLogrotate Version3.7.1
GentooLogrotate Version3.7.1 Updater1
GentooLogrotate Version3.7.1 Updater2
GentooLogrotate Version3.7.2
GentooLogrotate Version3.7.6
GentooLogrotate Version3.7.7
GentooLogrotate Version3.7.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.194
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.