Summary
The remote host is missing an update to mm
announced via advisory DSA 137-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20137-1
Insight
Marcus Meissner and Sebastian Krahmer discovered and fixed a temporary file vulnerability in the mm shared memory library. This problem can be exploited to gain root access to a machine running Apache which is linked against this library, if shell access to the user ``www-data'' is already available (which could easily be triggered through PHP).
This problem has been fixed in the upstream version 1.2.0 of mm, which will be uploaded to the unstable Debian distribution while this advisory is released. Fixed packages for potato (Debian 2.2) and woody (Debian 3.0) are linked below.
We recommend that you upgrade your libmm packages immediately.
Severity
Classification
-
CVE CVE-2002-0658 -
CVSS Base Score: 6.2
AV:L/AC:H/Au:N/C:C/I:C/A:C
Related Vulnerabilities