GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Tue Jan 10, 2006 8:19 pm Post subject: [ GLSA 200601-05 ] mod_auth_pgsql: Multiple format string vu |
|
|
Gentoo Linux Security Advisory
Title: mod_auth_pgsql: Multiple format string vulnerabilities (GLSA 200601-05)
Severity: high
Exploitable: remote
Date: January 10, 2006
Updated: December 30, 2007
Bug(s): #118096
ID: 200601-05
Synopsis
Format string vulnerabilities in mod_auth_pgsql may lead to the execution of arbitrary code.
Background
mod_auth_pgsql is an Apache2 module that allows user authentication against a PostgreSQL database.
Affected Packages
Package: www-apache/mod_auth_pgsql
Vulnerable: < 2.0.3
Unaffected: >= 2.0.3
Unaffected: < 1.0.0
Architectures: All supported architectures
Description
The error logging functions of mod_auth_pgsql fail to validate certain strings before passing them to syslog, resulting in format string vulnerabilities.
Impact
An unauthenticated remote attacker could exploit these vulnerabilities to execute arbitrary code with the rights of the user running the Apache2 server by sending specially crafted login names.
Workaround
There is no known workaround at this time.
Resolution
All mod_auth_pgsql users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=www-apache/mod_auth_pgsql-2.0.3" |
References
CVE-2005-3656
FrSIRT ADV-2006-0070
Last edited by GLSA on Sun Dec 30, 2007 4:17 am; edited 3 times in total |
|