Slackware Linux PHP Packages Insecure Linking Configuration Vulnerability
BID:10461
Info
Slackware Linux PHP Packages Insecure Linking Configuration Vulnerability
| Bugtraq ID: | 10461 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 02 2004 12:00AM |
| Updated: | Jun 02 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Bryce Nichols. |
| Vulnerable: |
Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 |
| Not Vulnerable: | |
Discussion
Slackware Linux PHP Packages Insecure Linking Configuration Vulnerability
Slackware Linux PHP Packages are reportedly affected by an insecure linking configuration vulnerability. This issue is due to a configuration error that links PHP to be linked against shared libraries in insecure directories.
This issue can be leveraged by an attacker to execute arbitrary code in the security context of the user running the affected PHP process; typically the user 'nobody'.
Slackware Linux PHP Packages are reportedly affected by an insecure linking configuration vulnerability. This issue is due to a configuration error that links PHP to be linked against shared libraries in insecure directories.
This issue can be leveraged by an attacker to execute arbitrary code in the security context of the user running the affected PHP process; typically the user 'nobody'.
Exploit / POC
Slackware Linux PHP Packages Insecure Linking Configuration Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Slackware Linux PHP Packages Insecure Linking Configuration Vulnerability
Solution:
Slackware Linux has released advisory SSA:2004-154-02 dealing with this issue. Please see the referenced advisory for more information.
Solution:
Slackware Linux has released advisory SSA:2004-154-02 dealing with this issue. Please see the referenced advisory for more information.
References
Slackware Linux PHP Packages Insecure Linking Configuration Vulnerability
References:
References:
- Slackware HomePage (Slackware)