Summary
The remote host is missing an update to link-grammar announced via advisory DSA 1432-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201432-1
Insight
Alin Rad Pop discovered that link-grammar, Carnegie Mellon University's link grammar parser for English, performed insufficient validation within its tokenizer, which could allow a malicious input file to execute arbitrary code.
For the stable distribution (etch), this problem has been fixed in version 4.2.2-4etch1.
For the old stable distribution (sarge), this package was not present.
For the unstable distribution (sid), this problem was fixed in version 4.2.5-1.
We recommend that you upgrade your link-grammar package.
Severity
Classification
-
CVE CVE-2007-5395 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities