CVE-2011-3626

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
27/01/2012
Last modified:
11/04/2025

Description

Double free vulnerability in the prepare_exec function in src/exec.c in Logsurfer 1.5b and earlier, and Logsurfer+ 1.7 and earlier, allows remote attackers to execute arbitrary commands via crafted strings in a log file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:drusus:logsurfer:*:*:*:*:*:*:*:* 1.5b (including)
cpe:2.3:a:drusus:logsurfer:1.1:*:*:*:*:*:*:*
cpe:2.3:a:drusus:logsurfer:1.2:*:*:*:*:*:*:*
cpe:2.3:a:drusus:logsurfer:1.3:*:*:*:*:*:*:*
cpe:2.3:a:drusus:logsurfer:1.4:*:*:*:*:*:*:*
cpe:2.3:a:drusus:logsurfer:1.5:*:*:*:*:*:*:*
cpe:2.3:a:drusus:logsurfer:1.5:beta:*:*:*:*:*:*
cpe:2.3:a:drusus:logsurfer:1.5:beta2:*:*:*:*:*:*
cpe:2.3:a:drusus:logsurfer:1.5a:*:*:*:*:*:*:*
cpe:2.3:a:drusus:logsurfer:1.41:*:*:*:*:*:*:*
cpe:2.3:a:kerry_thompson:logsurfer\+:*:*:*:*:*:*:*:* 1.7 (including)
cpe:2.3:a:kerry_thompson:logsurfer\+:1.5a:*:*:*:*:*:*:*
cpe:2.3:a:kerry_thompson:logsurfer\+:1.5b:*:*:*:*:*:*:*
cpe:2.3:a:kerry_thompson:logsurfer\+:1.6:*:*:*:*:*:*:*
cpe:2.3:a:kerry_thompson:logsurfer\+:1.6a:*:*:*:*:*:*:*