Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://silcnet.org/docs/changelog/SILC%20Toolkit%201.1.10 http://www.openwall.com/lists/oss-security/2009/09/03/5 http://www.vuxml.org/freebsd/24aa9970-9ccd-11de-af10-000c29a67389.html
Insight
The following package is affected: silc-toolkit
CVE-2009-3051
Multiple format string vulnerabilities in
lib/silcclient/client_entry.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client before 1.1.8, allow remote attackers to execute arbitrary code via format string specifiers in a nickname field, related to the (1) silc_client_add_client, (2) silc_client_update_client, and (3) silc_client_nickname_format functions.
Severity
Classification
-
CVE CVE-2009-3051 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities