Ubuntu Security Notice (C) 2011-2013 Canonical, Inc. / NASL script (C) 2011-2013 Tenable Network Security, Inc.
The remote Ubuntu host is missing a security-related patch.
Dominik George discovered that logwatch did not properly sanitize log
file names that were passed to the shell as part of a command. If a
remote attacker were able to generate specially crafted filenames (for
example, via Samba logging), they could execute arbitrary code with
Update the affected logwatch package.
Risk factor :
Critical / CVSS Base Score : 10.0
CVSS Temporal Score : 7.8
Public Exploit Available : true