Summary
The remote host is missing an update to most
announced via advisory DSA 076-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20076-1
Insight
Pavel Machek has found a buffer overflow in the `most' pager program.
The problem is part of most's tab expansion where the program would write beyond the bounds two array variables when viewing a malicious file. This could lead into other data structures being overwritten which in turn could enable most to execute arbitrary code being able to compromise the users environment.
This has been fixed in the upstream version 4.9.2 and an updated version of 4.9.0 for Debian GNU/Linux 2.2.
We recommend that you upgrade your most package immediately.
Severity
Classification
-
CVE CVE-2001-0961 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities