Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Gentoo: GLSA-200405-08 High: Pound Format String Remote Exec Threat

gentoo
Calendar Grey May 18, 2004
Scroller Gentoo
The Gentoo Linux Security Advisory GLSA 200405-08 warns of a critical vulnerability in Pound, a reverse proxy and load balancer, related to a format string flaw. This issue could be exploited to execute arbitrary code due to improper handling of user input, enabling attackers to manipulate application behavior. To mitigate risks, users should update Pound to the latest version that addresses this vulnerability, and conduct a thorough review of server configurations and access controls to strengthen security
There is a format string flaw in Pound, allowing remote execution of arbitrary code with the rights of the Pound process.

Summary

Gentoo Linux Security Advisory GLSA 200405-08 https://security.gentoo.org/ Severity: High Title: Pound format string vulnerability Date: May 18, 2004 Bugs: #50421 ID: 200405-08

Synopsis ======= There is a format string flaw in Pound, allowing remote execution of arbitrary code with the rights of the Pound process.
Background ========= Pound is a reverse proxy, load balancer and HTTPS front-end. It allows to distribute the load on several web servers and offers a SSL wrapper for web servers that do not support SSL directly.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-www/pound <= 1.5 >= 1.6
========== A format string flaw in the processing of syslog messages was discovered and c...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround