Summary
The remote host is missing updates announced in
advisory GLSA 200404-18.
Solution
All users are advised to upgrade to the latest available version of ssmtp.
# emerge sync
# emerge -pv '>=net-mail/ssmtp-2.60.7'
# emerge '>=net-mail/ssmtp-2.60.7'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200404-18 http://bugs.gentoo.org/show_bug.cgi?id=47918
http://bugs.gentoo.org/show_bug.cgi?id=48435
http://secunia.com/advisories/11378/
http://lists.debian.org/debian-security-announce/debian-security-announce-2004/msg00084.html
Insight
There are multiple format string vulnerabilities in the SSMTP package, which may allow an attacker to run arbitrary code with ssmtp's privileges (potentially root).
Severity
Classification
-
CVE CVE-2004-0156 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities