public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] [gentoo-announce] GLSA: libmm
@ 2002-07-31  8:51 Seemant Kulleen
  0 siblings, 0 replies; only message in thread
From: Seemant Kulleen @ 2002-07-31  8:51 UTC (permalink / raw
  To: gentoo-announce

- -----------------------------------------------------------------------
GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT
- -----------------------------------------------------------------------
PACKAGE         : mm - Shared Memory Abstraction library
SUMMARY         : security vulnerability in mm temp files.
DATE            : Wed Jul 31 08:44:26 UTC 2002
- -----------------------------------------------------------------------

OVERVIEW

There is a temp file vulnerability that can be used to gain root access on
a system running Apache.  Versions affected: dev-libs/mm-1.1.3-r1

DETAIL

PHP can be used to give the www-user shell access for systems running
Apache.  This temp file vulnerability can be exploited to use that to gain
root access.

This affects dev-libs/mm-1.1.3-r1

http://online.securityfocus.com/advisories/4315


SOLUTION

It is recommended that all Gentoo Linux users who are running apache
linked with mm update their systems as follows. Note, the new version will
be mm-1.2.1

emerge rsync
emerge dev-libs/mm

- ------------------------------------------------------------------------
aliz@gentoo.org
seemant@gentoo.org
drobbins@gentoo.org
- ------------------------------------------------------------------------

-- 
Seemant Kulleen
Developer and Project Co-ordinator,
Gentoo Linux					http://www.gentoo.org/~seemant
_______________________________________________
gentoo-announce mailing list
gentoo-announce@gentoo.org
http://lists.gentoo.org/mailman/listinfo/gentoo-announce


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2002-07-31  8:52 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-07-31  8:51 [gentoo-dev] [gentoo-announce] GLSA: libmm Seemant Kulleen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox