Summary
The remote host is missing updates announced in
advisory GLSA 200511-12.
Solution
The Scorched 3D package has been hard-masked until a new version correcting these flaws is released. In the meantime, current users are advised to unmerge the package:
# emerge --unmerge games-strategy/scorched3d
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200511-12 http://bugs.gentoo.org/show_bug.cgi?id=111421
http://seclists.org/lists/fulldisclosure/2005/Nov/0079.html
Insight
Multiple vulnerabilities in Scorched 3D allow a remote attacker to deny service or execute arbitrary code on game servers.
Severity
Classification
-
CVE CVE-2005-3486, CVE-2005-3487, CVE-2005-3488 -
CVSS Base Score: 7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
Related Vulnerabilities