Swatch Throttled Event Reporting Vulnerability
BID:4746
Info
Swatch Throttled Event Reporting Vulnerability
| Bugtraq ID: | 4746 |
| Class: | Design Error |
| CVE: |
CVE-2002-0896 |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Vulnerability discovery credited to SUZUKI Yasuhiro <[email protected]>. |
| Vulnerable: |
Swatch Swatch 3.0.4 Swatch Swatch 3.0.3 |
| Not Vulnerable: | |
Discussion
Swatch Throttled Event Reporting Vulnerability
Swatch is a freely available, open source log watching utility. It is available for the Unix and Linux platforms.
Under some circumstances, a message may not be reported by swatch. When an event occurs on a system numerous times, and swatch has placed a throttle on the event to prevent multiple alerts, swatch does not sufficiently handle events of the same type afterwards. When an event has occurred and alerts for the event are throttled, a bug in the swatch throttle code prevents swatch from reporting the event if it occurs a month later.
Swatch is a freely available, open source log watching utility. It is available for the Unix and Linux platforms.
Under some circumstances, a message may not be reported by swatch. When an event occurs on a system numerous times, and swatch has placed a throttle on the event to prevent multiple alerts, swatch does not sufficiently handle events of the same type afterwards. When an event has occurred and alerts for the event are throttled, a bug in the swatch throttle code prevents swatch from reporting the event if it occurs a month later.
Exploit / POC
Swatch Throttled Event Reporting Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
Solution / Fix
Swatch Throttled Event Reporting Vulnerability
Solution:
An interim patch for swatch 3.0.4 has been supplied by SUZUKI Yasuhiro <[email protected]>, available at http://plaza8.mbn.or.jp/~yswww/myself/swatch-en.html.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
An interim patch for swatch 3.0.4 has been supplied by SUZUKI Yasuhiro <[email protected]>, available at http://plaza8.mbn.or.jp/~yswww/myself/swatch-en.html.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Swatch Throttled Event Reporting Vulnerability
References:
References:
- Bug of swatch 3.0.4 in throttle (SUZUKI Yasuhiro
) - Swatch Homepage (Swatch)