Summary
The remote host is missing an update to sash
announced via advisory DSA 015-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20015-1
Insight
Versions of sash prior to 3.4-4 did not clone /etc/shadow properly which lead into readable files for anybody. This was fixed by the Debian maintainer.
This package only exists in stable, so if you are running unstable you won't see a bugfix unless you use the resources from the bottom of this message to the proper configuration.
We recommend you upgrade your sash package immediately.
Severity
Classification
-
CVE CVE-2001-0195 -
CVSS Base Score: 2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities