Prewikka: password disclosure — GLSA 201101-07

Due to a world-readable file, a local attacker can obtain the SQL database password used by Prewikka.

Affected packages

net-analyzer/prewikka on all architectures
Affected versions < 0.9.14-r2
Unaffected versions >= 0.9.14-r2

Background

Prewikka is a graphical front-end analysis console for the Prelude Hybrid IDS Framework.

Description

The permissions of the prewikka.conf file are set world readable.

Impact

A local attacker could obtain the SQL database password used by Prewikka.

Workaround

There is no known workaround at this time.

Resolution

All Prewikka users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-analyzer/prewikka-0.9.14-r2"

NOTE: This is a legacy GLSA. Updates for all affected architectures are available since May 18, 2009 . It is likely that your system is already no longer affected by this issue.

References

Release date
January 16, 2011

Latest revision
January 16, 2011: 01

Severity
normal

Exploitable
local

Bugzilla entries