Summary
The remote host is missing an update to procmail
announced via advisory DSA 083-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20083-1
Insight
Using older versions of procmail it was possible to make procmail crash by sending it signals. On systems where procmail is installed setuid this could be exploited to obtain unauthorized privileges.
This problem has been fixed in version 3.20 by the upstream maintainer, included in Debian unstable, and was ported back to version 3.15.2 which is available for for the stable Debian GNU/Linux 2.2.
We recommend that you upgrade your procmail package immediately.
Severity
Classification
-
CVE CVE-2001-0905 -
CVSS Base Score: 6.2
AV:L/AC:H/Au:N/C:C/I:C/A:C
Related Vulnerabilities