Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2002:059: php Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the php package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2002:059 (php).
A fifth parameter was added to PHP's mail() function in 4.0.5 that is not
properly sanitized when the server is running in safe mode. This vulnerability
would allow local users and, possibly, remote attackers to execute arbitrary
commands using shell metacharacters.
After upgrading to these packages, execute 'service httpd restart' as root in
order to close the hole immediately.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2002:059
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.