Bugzilla – Bug 674984
VUL-0: logwatch: Privilege escalation due improper sanitization of special characters in log file names
Last modified: 2011-03-30 12:44:19 UTC
Hi. There is a security bug in package 'logwatch'. This information is from 'oss-security'. This bug is public. There is no coordinated release date (CRD) set. CVE number: CVE-2011-1018 CVE description: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1018 CVSS v2 Base Score: 8.5 (important) (AV:N/AC:M/Au:S/C:C/I:C/A:C) Original posting: CVE-2011-1018 ---------- Weitergeleitete Nachricht ---------- Betreff: [oss-security] CVE Request -- logwatch: Privilege escalation due improper sanitization of special characters in log file names Datum: Donnerstag 24 Februar 2011 Von: Jan Lieskovsky <jlieskov@redhat.com> An: "Steven M. Christey" <coley@linus.mitre.org> Hello Josh, Steve, vendors, a security flaw was found in the way logwatch, a log file analysis program, pre-processed log files, containing certain special characters in their names. A remote attacker could use this flaw to execute arbitrary code with the privileges of the privileged system user (root) by creating a specially-crafted log file, subsequently analyzed by the logwatch script. Upstream bug report: [1] http://sourceforge.net/tracker/?func=detail&aid=3184223&group_id=312875&atid=1316824 Related patch: [2] http://logwatch.svn.sourceforge.net/viewvc/logwatch?view=revision&revision=26 Other references: [3] http://sourceforge.net/mailarchive/forum.php?thread_name=4D604843.7040303%40mblmail.net&forum_name=logwatch-devel [4] https://bugzilla.redhat.com/show_bug.cgi?id=680237 Could you allocate a CVE id for this issue? Thanks && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team -------------------------------------------------------------
Fixed packages for 11.2, 11.3, factory, sle11 sp1, sle10 sp3 and sle10 sp4 submitted in SRs 62800, 62803, 162804, 10896, 10897 and 10898. Thomas, will you do the needed patchinfo?
Yes, I will take care of the rest of the process. Thanks.
The SWAMPID for this issue is 38971. This issue was rated as important. Please submit fixed packages until 2011-03-04. When done, please reassign the bug to security-team@suse.de. Patchinfo will be handled by security team.
Update released for: logwatch Products: openSUSE 11.2 (i586) openSUSE 11.3 (i586)
released
Update released for: logwatch Products: SLE-SDK 10-SP3 (i386, ia64, ppc, s390x, x86_64)
Update released for: logwatch Products: SLE-SDK 10-SP4 (i386, ia64, ppc, s390x, x86_64)
Update released for: logwatch Products: SLE-SERVER 11-SP1 (i386, ia64, ppc64, s390x, x86_64) SLES4VMWARE 11-SP1 (i386, x86_64)