[MBT] new ticket for pkg mm "Privelige escalation in mm before 1.2.0 (for local Apache user)"

bugs at pld.org.pl bugs at pld.org.pl
Fri Feb 28 16:25:26 CET 2003


Date: 2003-02-28 16:25:26+01	Author:  (kreutzm) <kreutzm at itp.uni-hannover.de> 
Title:         Privelige escalation in mm before 1.2.0 (for local Apache user)
Ticket ID:     #587
Ticket URL:    http://bugs.pld.org.pl/?bug=587
Package:       mm-1.1.3-6
Distribution:  PLD-Ra.main PLD-1.0.devel.main PLD-1.0.devel.test PLD-1.0.devel.supported
Category:      security problem
Current state: opened
Text:

OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.

Please build version >= 1.2.0 for alpha && i386.

Thanks.



More information about the pld-bugs mailing list