Gentoo Archives: gentoo-announce

From: glsamaker@g.o
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202208-18 ] Motion: Denial of service
Date: Wed, 10 Aug 2022 22:49:02
Message-Id: 166017069033.8.11950295565425329184@a9099abfa3b1
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202208-18
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Low
8 Title: Motion: Denial of service
9 Date: August 10, 2022
10 Bugs: #760714
11 ID: 202208-18
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A vulnerability in Motion allows a remote attacker to cause denial of
19 service.
20
21 Background
22 ==========
23
24 Motion is a program that monitors the video signal from one or more
25 cameras and is able to detect motions.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 media-video/motion < 4.3.2 >= 4.3.2
34
35 Description
36 ===========
37
38 The Motion HTTP server does not correctly perform URL decoding. If the
39 HTTP server receives a request for a URL containing an incomplete
40 percent-encoded character, a flaw in parsing results in an infinite loop
41 trying to parse the rest of the character, which eventually results in a
42 denial of service condition when reading out-of-bounds.
43
44 Impact
45 ======
46
47 A remote attacker can trigger a denial of service condition in Motion.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All Motion users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=media-video/motion-4.3.2"
61
62 References
63 ==========
64
65 [ 1 ] CVE-2020-26566
66 https://nvd.nist.gov/vuln/detail/CVE-2020-26566
67
68 Availability
69 ============
70
71 This GLSA and any updates to it are available for viewing at
72 the Gentoo Security Website:
73
74 https://security.gentoo.org/glsa/202208-18
75
76 Concerns?
77 =========
78
79 Security is a primary focus of Gentoo Linux and ensuring the
80 confidentiality and security of our users' machines is of utmost
81 importance to us. Any security concerns should be addressed to
82 security@g.o or alternatively, you may file a bug at
83 https://bugs.gentoo.org.
84
85 License
86 =======
87
88 Copyright 2022 Gentoo Foundation, Inc; referenced text
89 belongs to its owner(s).
90
91 The contents of this document are licensed under the
92 Creative Commons - Attribution / Share Alike license.
93
94 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature