Summary
The remote host is missing an update to libapache-auth-ldap announced via advisory DSA 952-1.
Seregorn discovered a format string vulnerability in the logging function of libapache-auth-ldap, an LDAP authentication module for the Apache webserver, that can lead to the execution of arbitrary code.
For the old stable distribution (woody) this problem has been fixed in version 1.6.0-3.1.
Solution
For the stable distribution (sarge) this problem has been fixed in version 1.6.0-8.1
The unstable distribution (sid) does no longer contain libapache-auth-ldap.
We recommend that you upgrade your libapache-auth-ldap package.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20952-1
Severity
Classification
-
CVE CVE-2006-0150 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities