CVE-2011-1154

Gentoo Logrotate < 3.7.9 - Improper Input Validation

Title source: rule

Description

The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.

Scores

EPSS 0.0005
EPSS Percentile 15.7%

Classification

CWE
CWE-20
Status draft

Affected Products (14)

gentoo/logrotate < 3.7.9
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate

Timeline

Published Mar 30, 2011
Tracked Since Feb 18, 2026