|Category:||Red Hat Local Security Checks|
|Title:||RedHat Security Advisory RHSA-2011:0324|
The remote host is missing updates announced in
Logwatch is a customizable log analysis system. Logwatch parses through
your system's logs for a given period of time and creates a report
analyzing areas that you specify, in as much detail as you require.
A flaw was found in the way Logwatch processed log files. If an attacker
were able to create a log file with a malicious file name, it could result
in arbitrary code execution with the privileges of the root user when that
log file is analyzed by Logwatch. (CVE-2011-1018)
Users of logwatch should upgrade to this updated package, which contains a
backported patch to resolve this issue.
Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date
Risk factor : Critical
Common Vulnerability Exposure (CVE) ID: CVE-2011-1018|
BugTraq ID: 46554
Debian Security Information: DSA-2182 (Google Search)
SuSE Security Announcement: SUSE-SR:2011:005 (Google Search)
|Copyright||Copyright (c) 2011 E-Soft Inc. http://www.securityspace.com|
|This is only one of 97459 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.