logwatch.pl in Logwatch 7.3.6 allows remote malicious users to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
logwatch logwatch 7.3.6 |