Prewikka: password disclosure
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201101-07 / Prewikka |
| Release Date |
January 16, 2011 |
| Latest Revision |
January 16, 2011: 01 |
| Impact |
normal |
| Exploitable |
local |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-analyzer/prewikka |
<
0.9.14-r2 |
>=
0.9.14-r2 |
All supported architectures
|
Related bugreports:
#270056
Synopsis
Due to a world-readable file, a local attacker can obtain the SQL database
password used by Prewikka.
2.
Impact Information
Background
Prewikka is a graphical front-end analysis console for the Prelude
Hybrid IDS Framework.
Description
The permissions of the prewikka.conf file are set world readable.
Impact
A local attacker could obtain the SQL database password used by
Prewikka.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Prewikka users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-analyzer/prewikka-0.9.14-r2"
|
NOTE: This is a legacy GLSA. Updates for all affected architectures are
available since May 18, 2009 . It is likely that your system is already
no longer affected by this issue.
4.
References
|