Summary
The remote host is missing an update to htdig
announced via advisory DSA 680-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20680-1
Insight
Michael Krax discovered a cross site scripting vulnerability in ht://dig, a web search system for an intranet or small internet.
For the stable distribution (woody) this problem has been fixed in version 3.1.6-3woody1.
For the unstable distribution (sid) this problem has been fixed in version 3.1.6-11.
We recommend that you upgrade your htdig package.
Severity
Classification
-
CVE CVE-2005-0085 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities