Gentoo Archives: gentoo-announce

From: Stefan Behte <craig@g.o>
To: gentoo-announce@g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 201101-07 ] Prewikka: password disclosure
Date: Sun, 16 Jan 2011 13:11:46
Message-Id: 4D32D291.6060505@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201101-07
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Prewikka: password disclosure
9 Date: January 16, 2011
10 Bugs: #270056
11 ID: 201101-07
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Due to a world-readable file, a local attacker can obtain the SQL
19 database password used by Prewikka.
20
21 Background
22 ==========
23
24 Prewikka is a graphical front-end analysis console for the Prelude
25 Hybrid IDS Framework.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 net-analyzer/prewikka < 0.9.14-r2 >= 0.9.14-r2
34
35 Description
36 ===========
37
38 The permissions of the prewikka.conf file are set world readable.
39
40 Impact
41 ======
42
43 A local attacker could obtain the SQL database password used by
44 Prewikka.
45
46 Workaround
47 ==========
48
49 There is no known workaround at this time.
50
51 Resolution
52 ==========
53
54 All Prewikka users should upgrade to the latest version:
55
56 # emerge --sync
57 # emerge --ask --oneshot --verbose ">=net-analyzer/prewikka-0.9.14-r2"
58
59 NOTE: This is a legacy GLSA. Updates for all affected architectures are
60 available since May 18, 2009 . It is likely that your system is already
61 no longer affected by this issue.
62
63 References
64 ==========
65
66 [ 1 ] CVE-2010-2058
67 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2058
68
69 Availability
70 ============
71
72 This GLSA and any updates to it are available for viewing at
73 the Gentoo Security Website:
74
75 http://security.gentoo.org/glsa/glsa-201101-07.xml
76
77 Concerns?
78 =========
79
80 Security is a primary focus of Gentoo Linux and ensuring the
81 confidentiality and security of our users machines is of utmost
82 importance to us. Any security concerns should be addressed to
83 security@g.o or alternatively, you may file a bug at
84 https://bugs.gentoo.org.
85
86 License
87 =======
88
89 Copyright 2011 Gentoo Foundation, Inc; referenced text
90 belongs to its owner(s).
91
92 The contents of this document are licensed under the
93 Creative Commons - Attribution / Share Alike license.
94
95 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature