Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Date: Tue, 8 Mar 2011 10:59:03 -0600 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Important: logwatch on SL5.x, SL6.x i386/x86_64 Comments: To: " This email address is being protected from spambots. You need JavaScript enabled to view it. "Synopsis: Important: logwatch security update Issue date: 2011-03-07 CVE Names: CVE-2011-1018 A flaw was found in the way Logwatch processed log files. If an attacker were able to create a log file with a malicious file name, it could result in arbitrary code execution with the privileges of the root user when that log file is analyzed by Logwatch. (CVE-2011-1018) SL 5.x SRPMS: logwatch-7.3-9.el5_6.src.rpm i386: logwatch-7.3-9.el5_6.noarch.rpm x86_64: logwatch-7.3-9.el5_6.noarch.rpm SL 6.x SRPMS: logwatch-7.3.6-49.el6.src.rpm i386: logwatch-7.3.6-49.el6.noarch.rpm x86_64: logwatch-7.3.6-49.el6.noarch.rpm -Connie Sieh -Troy Dawson