Summary
The remote host is missing updates announced in
advisory GLSA 200404-19.
Solution
LCDproc users should upgrade to version 0.4.5 or later:
# emerge sync
# emerge -pv '>=app-misc/lcdproc-0.4.5'
# emerge '>=app-misc/lcdproc-0.4.5'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200404-19 http://bugs.gentoo.org/show_bug.cgi?id=47340
http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html
Insight
Multiple remote vulnerabilities have been found in the LCDd server, allowing execution of arbitrary code with the rights of the LCDd user.
Severity
Classification
-
CVE CVE-2004-1915, CVE-2004-1916, CVE-2004-1917 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities