Summary
The remote host is missing an update to the system as announced in the referenced advisory FreeBSD-SA-10:05.opie.asc
Solution
Upgrade your system to the appropriate stable release or security branch dated after the correction date
https://secure1.securityspace.com/smysecure/catid.html?in=FreeBSD-SA-10:05.opie.asc
Insight
OPIE is a one-time password system designed to help to secure a system against replay attacks. It does so using a secure hash function and a challenge/response system.
OPIE is enabled by default on FreeBSD.
A programming error in the OPIE library could allow an off-by-one buffer overflow to write a single zero byte beyond the end of an on-stack buffer.
Severity
Classification
-
CVE CVE-2010-1938 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities