Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.69394
Categoría:Mandrake Local Security Checks
Título:Mandriva Security Advisory MDVSA-2011:057 (apache)
Resumen:NOSUMMARY
Descripción:Description:
The remote host is missing an update to apache
announced via advisory MDVSA-2011:057.

The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk
Multi-Processing Module (apache-mpm-itk) for the Apache HTTP Server
does not properly handle certain configuration sections that specify
NiceValue but not AssignUserID, which might allow remote attackers to
gain privileges by leveraging the root uid and root gid of an mpm-itk
process (CVE-2011-1176).

Packages for 2009.0 are provided as of the Extended Maintenance
Program. Please visit this link to learn more:
http://store.mandriva.com/product_info.php?cPath=149&products_id=490

The updated packages uses the latest upstream ITK patch for apache
that is unaffected by this issue.

Affected: 2009.0, 2010.0, 2010.1, Enterprise Server 5.0

Solution:
To upgrade automatically use MandrakeUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

http://www.securityspace.com/smysecure/catid.html?in=MDVSA-2011:057

Risk factor : Medium

CVSS Score:
4.3

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-1176
BugTraq ID: 46953
http://www.securityfocus.com/bid/46953
Debian Security Information: DSA-2202 (Google Search)
http://www.debian.org/security/2011/dsa-2202
http://www.mandriva.com/security/advisories?name=MDVSA-2011:057
http://lists.err.no/pipermail/mpm-itk/2011-March/000393.html
http://lists.err.no/pipermail/mpm-itk/2011-March/000394.html
http://openwall.com/lists/oss-security/2011/03/20/1
http://openwall.com/lists/oss-security/2011/03/21/13
http://www.vupen.com/english/advisories/2011/0748
http://www.vupen.com/english/advisories/2011/0749
http://www.vupen.com/english/advisories/2011/0824
XForce ISS Database: apache-mtmitk-weak-security(66248)
https://exchange.xforce.ibmcloud.com/vulnerabilities/66248
CopyrightCopyright (c) 2011 E-Soft Inc. http://www.securityspace.com

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.