Fedora: Security Advisory for elog (FEDORA-2020-9f8bc040c8)

Published: 2020-01-27 09:26:07
CVE Author: NIST National Vulnerability Database (NVD)

CVSS Base Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Summary:
The remote host is missing an update for the 'elog' Linux Distribution Package(s) announced via the FEDORA-2020-9f8bc040c8 advisory.

Detection Method:
Checks if a vulnerable Linux Distribution Package version is present on the target host.

Technical Details:
ELOG is part of a family of applications known as weblogs. Their general purpose is: 1. To make it easy for people to put information online in a chronological fashion, in the form of short, time-stamped text messages ('entries') with optional HTML markup for presentation, and optional file attachments (images, archives, etc.) 2. To make it easy for other people to access this information through a Web interface, browse entries, search, download files, and optionally add, update, delete or comment on entries. ELOG is a remarkable implementation of a weblog in at least two respects: 1. Its simplicity of use: you don', t need to be a seasoned server operator and/or an experimented database administrator to run ELOG, one executable file (under Unix or Windows), a simple configuration text file, and it works. No Web server or relational database required. It is also easy to translate the interface to the appropriate language for your users. 2. Its versatility: through its single configuration file, ELOG can be made to display an infinity of variants of the weblog concept. There are options for what to display, how to display it, what commands are available and to whom, access control, etc. Moreover, a single server can host several weblogs, and each weblog can be totally different from the rest.

Affected Versions:
'elog' Linux Distribution Package(s) on Fedora 30.

Recommendations:
Please install the updated Linux Distribution Package(s).

Solution Type:
Vendor Patch

Detection Type:
Linux Distribution Package

NIST (National Institute of Standards and Technology) NVD (National Vulnerability Database)

https://nvd.nist.gov/vuln/detail/CVE-2019-3993
https://nvd.nist.gov/vuln/detail/CVE-2019-3994
https://nvd.nist.gov/vuln/detail/CVE-2019-3995
https://nvd.nist.gov/vuln/detail/CVE-2019-3992
https://nvd.nist.gov/vuln/detail/CVE-2019-3996

References:

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2IN3FP6VXYSD4OMUCFZNOL7MKPWRQFAL

Search
Severity
High
CVSS Score
7.5

You never have to pay for a vulnerability scanning and management software again.

Tired of paying a subscription 'per asset' or 'per IP'? Well you can officially cancel your current subscription. Mageni provides a free, open source and enterprise-ready vulnerability scanning and management platform which helps you to find, prioritize, remediate and manage your vulnerabilities. It is free and always will be.