[MBT] new ticket for pkg mm "Privelige escalation in mm before 1.2.0 (for local Apache user)"
bugs at pld.org.pl
bugs at pld.org.pl
Fri Feb 28 16:25:26 CET 2003
Date: 2003-02-28 16:25:26+01 Author: (kreutzm) <kreutzm at itp.uni-hannover.de>
Title: Privelige escalation in mm before 1.2.0 (for local Apache user)
Ticket ID: #587
Ticket URL: http://bugs.pld.org.pl/?bug=587
Package: mm-1.1.3-6
Distribution: PLD-Ra.main PLD-1.0.devel.main PLD-1.0.devel.test PLD-1.0.devel.supported
Category: security problem
Current state: opened
Text:
OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a symbolic link attack.
Please build version >= 1.2.0 for alpha && i386.
Thanks.
More information about the pld-bugs
mailing list