logrotate 'shred_file()' Log Filename Command Injection Vulnerability
BID:47103
Info
logrotate 'shred_file()' Log Filename Command Injection Vulnerability
| Bugtraq ID: | 47103 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1154 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 04 2011 12:00AM |
| Updated: | May 07 2015 05:06PM |
| Credit: | Florian Zumbiehl, Paul Martin, Stefan Fritsch <br> |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 11.04 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.10 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 LTS Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise 11 SP1 SuSE SUSE Linux Enterprise 10 SP4 SuSE SUSE Linux Enterprise 10 SP3 S.u.S.E. openSUSE 11.4 S.u.S.E. openSUSE 11.3 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node 6 Redhat Enterprise Linux Desktop 6 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 logrotate logrotate 3.7.9 Gentoo Linux |
| Not Vulnerable: | |
Discussion
logrotate 'shred_file()' Log Filename Command Injection Vulnerability
logrotate is prone to a command-injection vulnerability because it fails to adequately sanitize shell metacharacters from log filenames.
Attackers can exploit this issue to execute arbitrary commands with the permissions of the user running logrotate, typically the root user. Successful exploits can completely compromise an affected computer.
logrotate is prone to a command-injection vulnerability because it fails to adequately sanitize shell metacharacters from log filenames.
Attackers can exploit this issue to execute arbitrary commands with the permissions of the user running logrotate, typically the root user. Successful exploits can completely compromise an affected computer.
References
logrotate 'shred_file()' Log Filename Command Injection Vulnerability
References:
References:
- Bug 680796 - (CVE-2011-1154) CVE-2011-1154 logrotate: Shell command injection by (Jan Lieskovsky)
- CVE Request -- logrotate -- nine issues (Jan Lieskovsky)
- logrotate Product Page (logrotate)