Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.securityfocus.com/advisories/6874
http://www.vuxml.org/freebsd/2c5757f4-88bf-11d9-8720-0007e900f87b.html
Insight
The following package is affected: sup
CVE-2004-0451
Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary code via format string specifiers in messages that are logged by syslog.
Severity
Classification
-
CVE CVE-2004-0451 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities