Summary
The remote host is missing an update to groff
announced via advisory DSA 072-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20072-1
Insight
Zenith Parse found a security problem in groff (the GNU version of troff). The pic command was vulnerable to a printf format attack which made it possible to circumvent the -S option and execute arbitrary code.
This has been fixed in version 1.15.2-2.
Severity
Classification
-
CVE CVE-2001-1022 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities