Mandrake Linux Security Advisory : mod_php3 (MDKSA-2000:062)

critical Nessus Plugin ID 61849

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

PHP version 3 which ships with Linux-Mandrake are vulnerable to format string attacks due to logging functions that make improper use of the syslog() and vsnprintf() functions. This renders PHP3-enabled servers vulnerable to compromise by remote attackers. This attack is only effective on PHP installations that log errors and warnings while those servers that do not are not affected. By default, Linux-Mandrake systems do not have logging enabled.

Solution

Update the affected packages.

Plugin Details

Severity: Critical

ID: 61849

File Name: mandrake_MDKSA-2000-062.nasl

Version: 1.6

Type: local

Published: 9/6/2012

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:mod_php3, p-cpe:/a:mandriva:linux:mod_php3-imap, p-cpe:/a:mandriva:linux:mod_php3-ldap, p-cpe:/a:mandriva:linux:mod_php3-manual, p-cpe:/a:mandriva:linux:mod_php3-mysql, p-cpe:/a:mandriva:linux:mod_php3-pgsql, cpe:/o:mandrakesoft:mandrake_linux:6.1, cpe:/o:mandrakesoft:mandrake_linux:7.0, cpe:/o:mandrakesoft:mandrake_linux:7.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 10/12/2000

Reference Information

CVE: CVE-2000-0967

MDKSA: 2000:062