Summary
The remote host is missing an update to flim
announced via advisory DSA 500-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20500-1
Insight
Tatsuya Kinoshita discovered a vulnerability in flim, an emacs library for working with internet messages, where temporary files were created without taking appropriate precautions. This vulnerability could potentially be exploited by a local user to overwrite files with the privileges of the user running emacs. the 'chroot' option.
For the current stable distribution (woody) this problem has been fixed in version 1.14.3-9woody1.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you update your flim package.
Severity
Classification
-
CVE CVE-2004-0422 -
CVSS Base Score: 2.1
AV:L/AC:L/Au:N/C:N/I:P/A:N
Related Vulnerabilities