Prewikka: password disclosure Due to a world-readable file, a local attacker can obtain the SQL database password used by Prewikka. Prewikka 2011-01-16 2011-01-16 270056 local 0.9.14-r2 0.9.14-r2

Prewikka is a graphical front-end analysis console for the Prelude Hybrid IDS Framework.

The permissions of the prewikka.conf file are set world readable.

A local attacker could obtain the SQL database password used by Prewikka.

There is no known workaround at this time.

All Prewikka users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/prewikka-0.9.14-r2"

NOTE: This is a legacy GLSA. Updates for all affected architectures are available since May 18, 2009 . It is likely that your system is already no longer affected by this issue.

CVE-2010-2058 craig craig p-y