Double free vulnerability in the prepare_exec function in src/exec.c in Logsurfer 1.5b and earlier, and Logsurfer+ 1.7 and earlier, allows remote attackers to execute arbitrary commands via crafted strings in a log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Logsurfer | Drusus | 1.1 | 1.1 |
Logsurfer | Drusus | 1.2 | 1.2 |
Logsurfer | Drusus | 1.3 | 1.3 |
Logsurfer | Drusus | 1.4 | 1.4 |
Logsurfer | Drusus | 1.5 | 1.5 |
Logsurfer | Drusus | 1.5 | 1.5 |
Logsurfer | Drusus | 1.5 | 1.5 |
Logsurfer | Drusus | 1.5a | 1.5a |
Logsurfer | Drusus | * | 1.5b |
Logsurfer | Drusus | 1.41 | 1.41 |