Summary
The remote host is missing an update to openafs
announced via advisory DSA 142-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20142-1
Insight
An integer overflow bug has been discovered in the RPC library used by the OpenAFS database server, which is derived from the SunRPC library.
This bug could be exploited to crash certain OpenAFS servers (volserver, vlserver, ptserver, buserver) or to obtain unauthorized root access to a host running one of these processes. No exploits are known to exist yet.
This problem has been fixed in version 1.2.3final2-6 for the current stable distribution (woody) and in version 1.2.6-1 for the unstable distribution (sid). Debian 2.2 (potato) is not affected since it doesn't contain OpenAFS packages.
We recommend that you upgrade your openafs packages.
Severity
Classification
-
CVE CVE-2002-0391 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities