Release date: 2010-09-09
Updated on: 2010-09-20
Affected Systems:
Splunk 4.0-4.1.4
Unaffected system:
Splunk 4.1.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 43276
CVE (CAN) ID: CVE-2010-3322, CVE-2010-3323
Splunk is a log analysis software running in Unix environment.
Splunk XML Parser has a vulnerability in parsing XML internal entity references. Remote attackers can perform certain operations or leak certain information with higher permissions; in addition, if you log on with a special link, the session of another user may be hijacked.
<* Source: Aaron (lumpy@musicvision.com)
Link: http://secunia.com/advisories/41479/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Splunk
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.splunk.com/view/SP-CAAAFQ6