Summary
The remote host is missing an update to man-db
announced via advisory DSA 028-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20028-1
Insight
Styx has reported that the program `man' mistakenly passes malicious strings (i.e. containing format characters) through routines that were not meant to use them as format strings. Since this could cause a segmentation fault and privileges were not dropped it may lead to an exploit for the 'man' user.
We recommend you upgrade your man-db package immediately.
Severity
Classification
-
CVE CVE-2001-0193 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities