Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian DSA-967-1 Critical: Elog Remote Code Execution and DoS

debian
Calendar Grey February 10, 2006
Debian Logo
The Debian Security Notice highlights various vulnerabilities present in the elog software, which pose risks of remote code execution and denial of service.
Several security problems have been found in elog, an electonic logbook to manage notes

Summary


"GroundZero Security" discovered that elog insufficiently checks the
size of a buffer used for processing URL parameters, which might lead
to the execution of arbitrary code.

CVE-2006-0347

It was discovered that elog contains a directory traveral vulnerability
in the processing of "../" sequences in URLs, which might lead to
information disclosure.

CVE-2006-0348

The code to write the log file contained a format string vulnerability,
which might lead to the execution of arbitrary code.

CVE-2006-0597

Overly long revision attributes might trigger a crash due to a buffer
overflow.

CVE-2006-0598

The code to write the log file does not enforce bounds checks properly,
which might lead to the execution of arbitrary code.

CVE-2006-0599

elog emitted different errors messages for invalid passwords and invalid
users, which allows an attacker to probe for valid user names.

CVE-2006-0600

An attacker could be driven into infi...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here