Summary
The remote host is missing an update to libnss-ldap announced via advisory DSA 1430-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201430-1
Insight
It was reported that a race condition exists in libnss-ldap, an NSS module for using LDAP as a naming service, which could cause denial of service attacks when applications use pthreads.
This problem was spotted in the dovecot IMAP/POP server but potentially affects more programs.
For the stable distribution (etch), this problem has been fixed in version 251-7.5etch1.
For the old stable distribution (sarge), this problem has been fixed in version 238-1sarge1.
For the unstable distribution (sid), this problem has been fixed in version 256-1.
We recommend that you upgrade your libnss-ldap package.
Severity
Classification
-
CVE CVE-2007-5794 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:P/I:N/A:N
Related Vulnerabilities