Summary
The remote host is missing an update to clearsilver announced via advisory DSA 2355-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202355-1
Insight
Leo Iannacone and Colin Watson discovered a format string vulnerability in the Python bindings for the Clearsilver HTML template system, which may lead to denial of service or the execution of arbitrary code.
For the oldstable distribution (lenny), this problem has been fixed in version 0.10.4-1.3+lenny1.
For the stable distribution (squeeze), this problem has been fixed in version 0.10.5-1+squeeze1.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you upgrade your clearsilver packages.
Severity
Classification
-
CVE CVE-2011-4357 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities