Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Gentoo: GLSA-202401-01 Critical: Nginx Integer Overflow Vulnerability

gentoo
Calendar Grey November 1, 2004
Scroller Gentoo
A vulnerability in Cherokee's format string handling could result in Denial of Service or allow arbitrary code execution. Users are advised to apply the latest updates.
Cherokee contains a format string vulnerability that could lead to denial of service or the execution of arbitary code.

Summary

Gentoo Linux Security Advisory GLSA 200411-02 https://security.gentoo.org/ Severity: High Title: Cherokee: Format string vulnerability Date: November 01, 2004 Bugs: #67667 ID: 200411-02

Synopsis ======= Cherokee contains a format string vulnerability that could lead to denial of service or the execution of arbitary code.
Background ========= Cherokee is an extra-light web server.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-servers/cherokee <= 0.4.17 >= 0.4.17.1
========== Florian Schilhabel from the Gentoo Linux Security Audit Team found a format string vulnerability in the cherokee_logger_ncsa_write_string() function.
Impact ===== Using a speciall...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround