Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53400
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-137)
Summary:The remote host is missing an update for the Debian 'mm' package(s) announced via the DSA-137 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'mm' package(s) announced via the DSA-137 advisory.

Vulnerability Insight:
Marcus Meissner and Sebastian Krahmer discovered and fixed a temporary file vulnerability in the mm shared memory library. This problem can be exploited to gain root access to a machine running Apache which is linked against this library, if shell access to the user 'www-data' is already available (which could easily be triggered through PHP).

This problem has been fixed in the upstream version 1.2.0 of mm, which will be uploaded to the unstable Debian distribution while this advisory is released. Fixed packages for potato (Debian 2.2) and woody (Debian 3.0) are linked below.

We recommend that you upgrade your libmm packages immediately and restart your Apache server.

Affected Software/OS:
'mm' package(s) on Debian 3.0.

Solution:
Please install the updated package(s).

CVSS Score:
6.2

CVSS Vector:
AV:L/AC:H/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-0658
BugTraq ID: 5352
http://www.securityfocus.com/bid/5352
Bugtraq: 20020730 [OpenPKG-SA-2002.007] OpenPKG Security Advisory (mm) (Google Search)
Caldera Security Advisory: CSSA-2002-032.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-032.0.txt
Debian Security Information: DSA-137 (Google Search)
http://www.debian.org/security/2002/dsa-137
FreeBSD Security Advisory: FreeBSD-SN-02:05
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:05.asc
HPdes Security Advisory: HPSBTL0208-056
http://online.securityfocus.com/advisories/4392
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-045.php
RedHat Security Advisories: RHSA-2002:153
http://rhn.redhat.com/errata/RHSA-2002-153.html
RedHat Security Advisories: RHSA-2002:154
http://rhn.redhat.com/errata/RHSA-2002-154.html
RedHat Security Advisories: RHSA-2002:156
http://rhn.redhat.com/errata/RHSA-2002-156.html
http://www.redhat.com/support/errata/RHSA-2002-163.html
RedHat Security Advisories: RHSA-2002:164
http://rhn.redhat.com/errata/RHSA-2002-164.html
http://www.redhat.com/support/errata/RHSA-2003-158.html
SuSE Security Announcement: SuSE-SA:2002:028 (Google Search)
http://www.novell.com/linux/security/advisories/2002_028_mod_ssl.html
http://www.iss.net/security_center/static/9719.php
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.