Summary
The remote host is missing an update to netpbm-free announced via advisory DSA 426-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20426-1
Insight
netpbm is graphics conversion toolkit made up of a large number of single-purpose programs. Many of these programs were found to create temporary files in an insecure manner, which could allow a local attacker to overwrite files with the privileges of the user invoking a vulnerable netpbm tool.
For the current stable distribution (woody) these problems have been fixed in version 2:9.20-8.4.
For the unstable distribution (sid) these problems have been fixed in version 2:9.25-9.
We recommend that you update your netpbm-free package.
Severity
Classification
-
CVE CVE-2003-0924 -
CVSS Base Score: 3.7
AV:L/AC:H/Au:N/C:P/I:P/A:P
Related Vulnerabilities