Title: ELOG Web Logbook Multiple Remote Vulnerabilities
Severity: HIGH
Description:
ELOG Web Logbook is a freely available, open-source package designed to provide a logbook capable of being used through a web interface. It is available for Unix and Linux systems.
ELOG is prone to multiple remote vulnerabilities. The following specific issues have been identified:
- A buffer-overflow vulnerability. This issue occurs when the application deals with overly long revision attributes. Successful exploitation may result in the execution of arbitrary code, but this has not been confirmed. Failed attack attempts will most likely result in a crash of the application, effectively denying service to legitimate users.
- A second buffer-overflow vulnerability. In this case, there's a boundary-condition error in the code for writing log files. Successful exploitation may result in the execution of arbitrary code.
- An information-disclosure vulnerability during the login process. The application responds with different messages for invalid passwords and invalid users. The information obtained may aid an attacker in brute-force attacks.
- A denial-of-service vulnerability. This issue occurs when dealing with specially crafted 'fail' requests. An infinite redirection can occur, potentially leading to a denial-of-service condition.
Affected Products:
- Debian Linux 3.1.0
- Debian Linux 3.1.0 alpha
- Debian Linux 3.1.0 amd64
- Debian Linux 3.1.0 arm
- Debian Linux 3.1.0 hppa
- Debian Linux 3.1.0 ia-32
- Debian Linux 3.1.0 ia-64
- Debian Linux 3.1.0 m68k
- Debian Linux 3.1.0 mips
- Debian Linux 3.1.0 mipsel
- Debian Linux 3.1.0 ppc
- Debian Linux 3.1.0 s/390
- Debian Linux 3.1.0 sparc
- Elog Web Logbook Elog Web Logbook 2.0.0.0
- Elog Web Logbook Elog Web Logbook 2.0.1
- Elog Web Logbook Elog Web Logbook 2.0.2
- Elog Web Logbook Elog Web Logbook 2.0.3
- Elog Web Logbook Elog Web Logbook 2.0.4
- Elog Web Logbook Elog Web Logbook 2.0.5
- Elog Web Logbook Elog Web Logbook 2.1.0.0
- Elog Web Logbook Elog Web Logbook 2.1.1
- Elog Web Logbook Elog Web Logbook 2.1.2
- Elog Web Logbook Elog Web Logbook 2.1.3
- Elog Web Logbook Elog Web Logbook 2.2.0.0
- Elog Web Logbook Elog Web Logbook 2.2.1
- Elog Web Logbook Elog Web Logbook 2.2.2
- Elog Web Logbook Elog Web Logbook 2.2.3
- Elog Web Logbook Elog Web Logbook 2.2.4
- Elog Web Logbook Elog Web Logbook 2.4.0
- Elog Web Logbook Elog Web Logbook 2.5.0
- Elog Web Logbook Elog Web Logbook 2.5.6
- Elog Web Logbook Elog Web Logbook 2.5.7
- Elog Web Logbook Elog Web Logbook 2.6.0 .0
- Elog Web Logbook Elog Web Logbook 2.6.1
References:
- Elog Web Logbook: Elog Web Logbook Homepage
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.