Summary
The remote host is missing an update to webfs
announced via advisory DSA 328-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20328-1
Insight
webfs, a lightweight HTTP server for static content, contains a buffer overflow whereby a long Request-URI in an HTTP request could cause arbitrary code to be executed.
For the stable distribution (woody) this problem has been fixed in version 1.17.1.
The old stable distribution (potato) does not contain a webfs package.
For the unstable distribution (sid) this problem will be fixed soon.
We recommend that you update your webfs package.
Severity
Classification
-
CVE CVE-2003-0445 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities