The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation86 reference(s) from NVD