PT-2002-3171 · Debian+1 · Libmm+1
Published
1970-01-01
·
Updated
2013-09-04
·
CVE-2002-0658
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libmm versions prior to 1.2.0
libmm10 (affected versions not specified)
libmm10-dev (affected versions not specified)
libmm11 (affected versions not specified)
libmm11-dev (affected versions not specified)
Description
The issue concerns multiple vulnerabilities in the libmm package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. The vulnerabilities may allow the local Apache user to gain privileges via temporary files, possibly through a symbolic link attack.
Recommendations
For libmm versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue.
For libmm10, libmm10-dev, libmm11, and libmm11-dev, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Http Server
Libmm