Summary
The remote host is missing an update to unzip
announced via advisory DSA 1522-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201522-1
Insight
Tavis Ormandy discovered that unzip, when processing specially crafted ZIP archives, could pass invalid pointers to the C library's free routine, potentially leading to arbitrary code execution (CVE-2008-0888).
For the stable distribution (etch), this problem has been fixed in version 5.52-9etch1.
For the old stable distribution (sarge), this problem has been fixed in version 5.52-1sarge5.
The unstable distribution (sid) will be fixed soon.
We recommend that you upgrade your unzip package.
Severity
Classification
-
CVE CVE-2008-0888 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities