Summary
The remote host is missing an update to advi
announced via advisory DSA 1912-2.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201912-2
Insight
Due to the fact that advi, an active DVI previewer and presenter, statically links against camlimages it was neccessary to rebuilt it in order to incorporate the latest security fixes for camlimages, which could lead to integer overflows via specially crafted TIFF files (CVE-2009-3296) or GIFF and JPEG images (CVE-2009-2660).
For the stable distribution (lenny), these problems have been fixed in version 1.6.0-13+lenny2.
Due to a bug in the archive system, the fix for the oldstable distribution (etch) cannot be released at the same time. These problems will be fixed in version 1.6.0-12+etch2, once it is available.
For the testing distribution (squeeze) and the unstable distribution (sid), these problems have been fixed in version 1.6.0-14+b1.
We recommend that you upgrade your advi package.
Severity
Classification
-
CVE CVE-2009-2660, CVE-2009-3296 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities