Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://bugs.gentoo.org/show_bug.cgi?id=79762
http://www.vuxml.org/freebsd/310d0087-0fde-4929-a41f-96f17c5adffe.html
Insight
The following packages are affected:
xli
xloadimage
CVE-2005-0638
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.
Severity
Classification
-
CVE CVE-2005-0638 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities