Summary
The remote host is missing an update to leksbot
announced via advisory DSA 299-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20299-1
Insight
Maurice Massar discovered that, due to a packaging error, the program /usr/bin/KATAXWR was inadvertently installed setuid root. This program was not designed to run setuid, and contained multiple vulnerabilities which could be exploited to gain root privileges.
For the stable distribution (woody) this problem has been fixed in version 1.2-3.1.
The old stable distribution (potato) does not contain a leksbot package.
For the unstable distribution (sid) this problem has been fixed in version 1.2-5.
We recommend that you update your leksbot package.
Severity
Classification
-
CVE CVE-2003-0262 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities