Analog contains a flaw that allows a local user to create a denial of service. The issue is due to the anlgform.pl (CGI front end to the Analog package) not preventing all privileged commands from being run by untrusted users. If an attacker uses the PROGRESSFREQ command they can set updates to be written very frequently, filling up the web server error log and exhausting disk space.
Classification
Attack Type:
Denial of Service
Impact:
Loss of Availability
Technical
This vulnerability only affects users who have installed the optional form interface to analog, anlgform.pl, and made it available to untrusted users.
Solution
Upgrade to version 5.23 or higher, as it has been reported to fix this
vulnerability. An upgrade is required as there are no known workarounds.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.