Summary
The remote host is missing an update to epic4-script-light announced via advisory DSA 156-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20156-1
Insight
All versions of the EPIC script Light prior to 2.7.30p5 (on the 2.7 branch) and prior to 2.8pre10 (on the 2.8 branch) running on any platform are vulnerable to a remotely-exploitable bug, which can lead to nearly arbitrary code execution.
This problem has been fixed in version 2.7.30p5-1.1 for the current stable distribution (woody) and in version 2.7.30p5-2 for the unstable distribution (sid). The old stable distribution (potato) is not affected, since it doesn't contain the Light package.
We recommend that you upgrade your epic4-script-light package and
Severity
Classification
-
CVE CVE-2002-0984 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities