Summary
The remote host is missing an update to kfreebsd-8 announced via advisory DSA 2325-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202325-1
Insight
Buffer overflow in the linux emulation support in FreeBSD kernel allows local users to cause a denial of service (panic) and possibly execute arbitrary code by calling the bind system call with a long path for a UNIX-domain socket, which is not properly handled when the address is used by other unspecified system calls.
For the stable distribution (squeeze), this problem has been fixed in version 8.1+dfsg-8+squeeze2.
For the unstable distribution (sid), this problem has been fixed in version 8.2-9.
We recommend that you upgrade your kfreebsd-8 packages.
Severity
Classification
-
CVE CVE-2011-4062 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities