Summary
The remote host is missing an update to id3lib3.8.3 announced via advisory DSA 1365-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201365-1
Insight
Nikolaus Schulz discovered that a programming error in id3lib, an ID3 Tag Library, may lead to denial of service through symlink attacks.
For the oldstable distribution (sarge) this problem has been fixed in version 3.8.3-4.1sarge1.
Due to a technical limitation in the archive management scripts the fix for the stable distribution (etch) can only be released in a few days.
For the unstable distribution (sid) this problem has been fixed in version 3.8.3-7.
We recommend that you upgrade your id3lib3.8.3 packages.
Severity
Classification
-
CVE CVE-2007-4460 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities