CVE-2011-1154
Gentoo Logrotate < 3.7.9 - Improper Input Validation
Title source: ruleDescription
The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
References (43)
... and 23 more
Scores
EPSS
0.0005
EPSS Percentile
15.7%
Classification
CWE
CWE-20
Status
draft
Affected Products (14)
gentoo/logrotate
< 3.7.9
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
gentoo/logrotate
Timeline
Published
Mar 30, 2011
Tracked Since
Feb 18, 2026