Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://lftp.yar.ru/news.html#2.6.10
http://www.vuxml.org/freebsd/d7af61c8-2cc0-11d8-9355-0020ed76ef5a.html
Insight
The following package is affected: lftp
CVE-2003-0963
Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.
Severity
Classification
-
CVE CVE-2003-0963 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities