Summary
The remote host is missing an update to libast, libast1 announced via advisory DSA 976-1.
Johnny Mast discovered a buffer overflow in libast, the library of assorted spiffy things, that can lead to the execution of arbitary code. This library is used by eterm which is installed setgid uid which leads to a vulnerability to alter the utmp file.
For the old stable distribution (woody) this problem has been fixed in version 0.4-3woody2.
Solution
For the stable distribution (sarge) this problem has been fixed in version 0.6-0pre2003010606sarge1.
For the unstable distribution (sid) this problem will be fixed soon.
We recommend that you upgrade your libast packages.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20976-1
Severity
Classification
-
CVE CVE-2006-0224 -
CVSS Base Score: 4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities