Summary
The remote host is missing an update to gpm
announced via advisory DSA 095-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20095-1
Insight
The package 'gpm' contains the 'gpm-root' program, which can be used to create mouse-activated menus on the console.
Among other problems, the gpm-root program contains a format string vulnerability, which allows an attacker to gain root privileges.
This has been fixed in version 1.17.8-18.1, and we recommend that you upgrade
Severity
Classification
-
CVE CVE-2001-1203 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities