7.5

CVE-2011-3626

Double free vulnerability in the prepare_exec function in src/exec.c in Logsurfer 1.5b and earlier, and Logsurfer+ 1.7 and earlier, allows remote attackers to execute arbitrary commands via crafted strings in a log file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DrususLogsurfer Version <= 1.5b
DrususLogsurfer Version1.1
DrususLogsurfer Version1.2
DrususLogsurfer Version1.3
DrususLogsurfer Version1.4
DrususLogsurfer Version1.5
DrususLogsurfer Version1.5 Updatebeta
DrususLogsurfer Version1.5 Updatebeta2
DrususLogsurfer Version1.5a
DrususLogsurfer Version1.41
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.18% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/46389
Vendor Advisory
http://secunia.com/advisories/47725
Vendor Advisory
http://security.gentoo.org/glsa/glsa-201201-04.xml
Vendor Advisory
http://www.openwall.com/lists/oss-security/2011/10/17/2
Patch
http://www.openwall.com/lists/oss-security/2011/10/17/4
https://bugs.gentoo.org/show_bug.cgi?id=387397
Patch
Vendor Advisory