Summary
The remote host is missing updates announced in
advisory GLSA 200411-31.
Solution
Currently, there is no released version of ProZilla that contains a fix for these issues. The original author did not respond to our queries, the code contains several other problems and more secure alternatives exist.
Therefore, the ProZilla package has been hard-masked prior to complete removal from Portage, and current users are advised to unmerge the package.
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200411-31 http://bugs.gentoo.org/show_bug.cgi?id=70090
Insight
ProZilla contains several buffer overflow vulnerabilities that can be exploited by a malicious server to execute arbitrary code with the rights of the user running ProZilla.
Severity
Classification
-
CVE CVE-2004-1120 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities