Summary
The remote host is missing an update to ruby1.8
announced via advisory DSA 748-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20748-1
Insight
A vulnerability has been discovered in ruby1.8 that could allow arbitrary command execution on a server running the ruby xmlrpc server.
The old stable distribution (woody) did not include ruby1.8.
This problem is fixed for the current stable distribution (sarge) in version 1.8.2-7sarge1.
This problem is fixed for the unstable distribution in version 1.8.2-8.
We recommend that you upgrade your ruby1.8 package.
Severity
Classification
-
CVE CVE-2005-1992 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities