Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://xforce.iss.net/xforce/xfdb/16996
http://www.debian.org/security/2004/dsa-537
http://marc.theaimsgroup.com/?l=bugtraq&m=109267579822250&w=2 http://www.vuxml.org/freebsd/e811aaf1-f015-11d8-876f-00902714cc7c.html
Insight
The following package is affected: ruby
CVE-2004-0755
The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.
Severity
Classification
-
CVE CVE-2004-0755 -
CVSS Base Score: 2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities