Summary
The remote host is missing an update to clamav
announced via advisory DSA 955-1.
Two denial of service bugs were found in the mailman list server. In one, attachment filenames containing UTF8 strings were not properly parsed, which could cause the server to crash. In another, a message containing a bad date string could cause a server crash.
The old stable distribution (woody) is not vulnerable to this issue.
Solution
For the stable distribution (sarge) this problem has been fixed in version 2.1.5-8sarge1.
For the unstable distribution (sid) this problem has been fixed in version 2.1.5-10.
We recommend that you upgrade your mailman package immediately.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20955-1
Severity
Classification
-
CVE CVE-2005-3573, CVE-2005-4153 -
CVSS Base Score: 7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities