Summary
The remote host is missing an update to zonecheck
announced via advisory DSA 2056-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202056-1
Insight
It was discovered that in zonecheck, a tool to check DNS configurations, the CGI does not perform sufficient sanitation of user input an
attacker can take advantage of this and pass script code in order to perform cross-site scripting attacks.
For the stable distribution (lenny), this problem has been fixed in version 2.0.4-13lenny1.
For the testing distribution (squeeze), this problem has been fixed in version 2.1.1-1.
For the testing distribution (sid), this problem has been fixed in version 2.1.1-1.
We recommend that you upgrade your zonecheck packages.
Severity
Classification
-
CVE CVE-2009-4882, CVE-2010-2155 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities