Summary
The remote host is missing updates announced in
advisory GLSA 200407-07.
Solution
All users should upgrade to the latest available version of Shorewall, as follows:
# emerge sync
# emerge -pv '>=net-firewall/shorewall-1.4.10f'
# emerge '>=net-firewall/shorewall-1.4.10f'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200407-07 http://bugs.gentoo.org/show_bug.cgi?id=55675
http://lists.shorewall.net/pipermail/shorewall-announce/2004-June/000385.html
Insight
Shorewall contains a bug in the code handling the creation of temporary files and directories. This can allow a non-root user to overwrite arbitrary system files.
Severity
Classification
-
CVE CVE-2004-0647 -
CVSS Base Score: 4.6
AV:L/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities