Summary
The remote host is missing an update to elinks
announced via advisory DSA 1902-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201902-1
Insight
Jakub Wilk discovered an off-by-one buffer overflow in the charset handling of elinks, a feature-rich text-mode WWW browser, which might lead to the execution of arbitrary code if the user is tricked into opening a malformed HTML page.
For the old stable distribution (etch), this problem has been fixed in version 0.11.1-1.2etch2.
The stable distribution (lenny) and the unstable distribution (sid) already contain a patch for this problem.
We recommend that you upgrade your elinks package.
Severity
Classification
-
CVE CVE-2008-7224 -
CVSS Base Score: 7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities