Summary
The remote host is missing an update to iproute
announced via advisory DSA 492-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20492-1
Insight
Herbert Xu reported that local users could cause a denial of service against iproute, a set of tools for controlling networking in Linux kernels. iproute uses the netlink interface to communicate with the kernel, but failed to verify that the messages it received came from the kernel (rather than from other user processes).
For the current stable distribution (woody) this problem has been fixed in version 20010824-8woody1.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you update your iproute package.
Severity
Classification
-
CVE CVE-2003-0856 -
CVSS Base Score: 4.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities