Summary
The remote host is missing an update to tinymux
announced via advisory DSA 1317-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201317-1
Insight
duskwave discovered that tinymux, a text-based multi-user virtual world server, performs insufficient boundary checks when working with user-supplied data, which might lead to the execution of arbitary code.
For the stable distribution (etch), this problem has been fixed in version 2.4.3.31-1etch1.
We recommend that you upgrade your tinymux package.
Severity
Classification
-
CVE CVE-2007-1655 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities