Fedora 8 : mod_suphp-0.6.3-1.fc8 (2008-2868)

This script is Copyright (C) 2008-2015 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

This update is a security update fixing two local privilege escalation
problems. mod_suphp 0.6.2 contains two race condition regarding
symlink checks. Using this attack vector a local attacker has the
ability of changing symlinks in the timeframe between the security
check and the php execution itself, leading suphp to execute code as
another local user. These have been fixed in the 0.6.3 update with no
further code changes being present making a backport of the security
fix unnecessary.

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

https://bugzilla.redhat.com/show_bug.cgi?id=439687
http://www.nessus.org/u?c8c93757

Solution :

Update the affected mod_suphp package.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:L/AC:L/Au:S/C:P/I:P/A:P)

Family: Fedora Local Security Checks

Nessus Plugin ID: 31748 (fedora_2008-2868.nasl)

Bugtraq ID:

CVE ID: CVE-2008-1614

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now