Summary
The remote host is missing an update to slocate
announced via advisory DSA 252-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20252-1
Insight
A problem has been discovered in slocate, a secure locate replacement.
A buffer overflow in the setuid program slocate can be used to execute arbitrary code as superuser.
For the stable distribution (woody) this problem has been fixed in version 2.6-1.3.1.
The old stable distribution (potato) is not affected by this problem.
For the unstable distribution (sid) this problem has been fixed in version 2.7-1.
We recommend that you upgrade your slocate package immediately.
Severity
Classification
-
CVE CVE-2003-0056 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities