Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://pear.php.net/advisory20091114-01.txt
http://www.vuxml.org/freebsd/56ba8728-f987-11de-b28d-00215c6a37bb.html
Insight
The following packages are affected:
pear-Net_Ping
pear-Net_Traceroute
CVE-2009-4024
Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter.
CVE-2009-4025
Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: some of these details are obtained from third party information.
Severity
Classification
-
CVE CVE-2009-4024, CVE-2009-4025 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities