Mandrake Linux Security Advisory : php (MDKSA-2003:082-1)

high Nessus Plugin ID 14064

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

A vulnerability was discovered in the transparent session ID support in PHP4 prior to version 4.3.2. It did not properly escape user- supplied input prior to inserting it in the generated web page. This could be exploited by an attacker to execute embedded scripts within the context of the generated HTML (CVE-2003-0442).

As well, two vulnerabilities had not been patched in the PHP packages included with Mandrake Linux 8.2: The mail() function did not filter ASCII control filters from its arguments, which could allow an attacker to modify the mail message content (CVE-2002-0986). Another vulnerability in the mail() function would allow a remote attacker to bypass safe mode restrictions and modify the command line arguments passed to the MTA in the fifth argument (CVE-2002-0985).

All users are encouraged to upgrade to these patched packages.

Update :

The packages for Mandrake Linux 8.2 and Multi-Network Firewall 8.2, due to improper BuildRequires did not include mail() support. This update corrects that problem.

Solution

Update the affected packages.

Plugin Details

Severity: High

ID: 14064

File Name: mandrake_MDKSA-2003-082.nasl

Version: 1.26

Type: local

Published: 7/31/2004

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.8

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:mandrakesoft:mandrake_linux:9.1, p-cpe:/a:mandriva:linux:libphp_common430, p-cpe:/a:mandriva:linux:php, p-cpe:/a:mandriva:linux:php-cgi, p-cpe:/a:mandriva:linux:php-cli, p-cpe:/a:mandriva:linux:php-common, p-cpe:/a:mandriva:linux:php-devel, p-cpe:/a:mandriva:linux:php-pear, p-cpe:/a:mandriva:linux:php430-devel, cpe:/o:mandrakesoft:mandrake_linux:8.2, cpe:/o:mandrakesoft:mandrake_linux:9.0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 8/4/2003

Reference Information

CVE: CVE-2002-0985, CVE-2002-0986, CVE-2003-0442

MDKSA: 2003:082, 2003:082-1