Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200411-02 ] Cherokee: Format string vulnerability
Date: Mon, 01 Nov 2004 18:12:59
Message-Id: 200411011905.22819.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200411-02
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Cherokee: Format string vulnerability
9 Date: November 01, 2004
10 Bugs: #67667
11 ID: 200411-02
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Cherokee contains a format string vulnerability that could lead to
19 denial of service or the execution of arbitary code.
20
21 Background
22 ==========
23
24 Cherokee is an extra-light web server.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 www-servers/cherokee <= 0.4.17 >= 0.4.17.1
33
34 Description
35 ===========
36
37 Florian Schilhabel from the Gentoo Linux Security Audit Team found a
38 format string vulnerability in the cherokee_logger_ncsa_write_string()
39 function.
40
41 Impact
42 ======
43
44 Using a specially crafted URL when authenticating via auth_pam, a
45 malicious user may be able to crash the server or execute arbitrary
46 code on the target machine with permissions of the user running
47 Cherokee.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All Cherokee users should upgrade to the latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=www-servers/cherokee-0.4.17.1"
61
62 Availability
63 ============
64
65 This GLSA and any updates to it are available for viewing at
66 the Gentoo Security Website:
67
68 http://security.gentoo.org/glsa/glsa-200411-02.xml
69
70 Concerns?
71 =========
72
73 Security is a primary focus of Gentoo Linux and ensuring the
74 confidentiality and security of our users machines is of utmost
75 importance to us. Any security concerns should be addressed to
76 security@g.o or alternatively, you may file a bug at
77 http://bugs.gentoo.org.
78
79 License
80 =======
81
82 Copyright 2004 Gentoo Foundation, Inc; referenced text
83 belongs to its owner(s).
84
85 The contents of this document are licensed under the
86 Creative Commons - Attribution / Share Alike license.
87
88 http://creativecommons.org/licenses/by-sa/1.0