Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.gentoo.org/security/en/glsa/glsa-200604-10.xml http://www.vuxml.org/freebsd/a813a219-d2d4-11da-a672-000e0c2e438a.html
Insight
The following packages are affected:
zgv
xzgv
CVE-2006-1060
Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-complicit attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required.
Severity
Classification
-
CVE CVE-2006-1060 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities