| PROBLEM: | It was discovered that suphp, an Apache module to run PHP scripts with owner permissions handles symlinks insecurely, which may lead to privilege escalation by local users. |
| PLATFORM: | Debian GNU/Linux 4.0 (stable) |
| DAMAGE: | Privilege escalation. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is LOW. May lead to privilege escalation by local users. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
3.2 2.6 (AV:L/AC:L/Au:S/C:P/I:P/A:N/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-278.shtml |
| ORIGINAL BULLETIN: | http://www.debian.org/security/2008/dsa-1550 |
| CVE: | CVE-2008-1614 |
[***** Start Debian Security Advisory DSA-1550-1 *****]
It was discovered that suphp, an Apache module to run PHP scripts with owner permissions handles symlinks insecurely, which may lead to privilege escalation by local users.
For the stable distribution (etch), this problem has been fixed in version 0.6.2-1+etch0.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you upgrade your suphp packages.
MD5 checksums of the listed files are available in the original advisory.
[***** End Debian Security Advisory DSA-1550-1 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org