GLSA Veteran

Joined: 12 May 2004 Posts: 1165
|
Posted: Sun Mar 29, 2009 10:26 pm Post subject: [ GLSA 200903-40 ] Analog: Denial of Service |
|
|
Gentoo Linux Security Advisory
Title: Analog: Denial of Service (GLSA 200903-40)
Severity: normal
Exploitable: local
Date: March 29, 2009
Bug(s): #249140
ID: 200903-40
Synopsis
A Denial of Service vulnerability was discovered in Analog.
Background
Analog is a a webserver log analyzer.
Affected Packages
Package: app-admin/analog
Vulnerable: < 6.0-r2
Unaffected: >= 6.0-r2
Architectures: All supported architectures
Description
Diego E. Petteno reported that the Analog package in Gentoo is built
with its own copy of bzip2, making it vulnerable to CVE-2008-1372 (GLSA
200804-02).
Impact
A local attacker could place specially crafted log files into a log
directory being analyzed by analog, e.g. /var/log/apache, resulting in
a crash when being processed by the application.
Workaround
There is no known workaround at this time.
Resolution
All Analog users should upgrade to the latest version:
| Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-admin/analog-6.0-r2" |
NOTE: Analog is now linked against the system bzip2 library.
References
CVE-2008-1372
GLSA 200804-02
Last edited by GLSA on Mon Oct 17, 2011 4:27 am; edited 2 times in total |
|