PT-2002-3171 · Debian+1 · Libmm+1

Published

1970-01-01

·

Updated

2013-09-04

·

CVE-2002-0658

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libmm versions prior to 1.2.0 libmm10 (affected versions not specified) libmm10-dev (affected versions not specified) libmm11 (affected versions not specified) libmm11-dev (affected versions not specified)
Description The issue concerns multiple vulnerabilities in the libmm package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. The vulnerabilities may allow the local Apache user to gain privileges via temporary files, possibly through a symbolic link attack.
Recommendations For libmm versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue. For libmm10, libmm10-dev, libmm11, and libmm11-dev, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-04062
BDU:2015-04063
BDU:2015-04064
BDU:2015-04065
CVE-2002-0658
DSA-137

Affected Products

Apache Http Server
Libmm