Summary
The remote host is missing updates announced in
advisory GLSA 200311-04.
Solution
Users are encouraged to perform an 'emerge sync' and upgrade the package to the latest available version - 0.9.3 is available in portage and is marked as stable.
# emerge sync
# emerge -pv '>=net-dialup/freeradius-0.9.3'
# emerge '>=net-dialup/freeradius-0.9.3'
# emerge clean
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200311-04 http://bugs.gentoo.org/show_bug.cgi?id=33989
http://www.securitytracker.com/alerts/2003/Nov/1008263.html
Insight
FreeRADIUS is vulnerable to a heap exploit and a NULL pointer dereference vulnerability.