Summary
The remote host is missing updates announced in
advisory GLSA 200805-03.
Solution
All aterm users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=x11-terms/aterm-1.0.1-r1'
All Eterm users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=x11-terms/eterm-0.9.4-r1'
All Mrxvt users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=x11-terms/mrxvt-0.5.3-r2'
All multi-aterm users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=x11-terms/multi-aterm-0.2.1-r1'
All RXVT users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=x11-terms/rxvt-2.7.10-r4'
All rxvt-unicode users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=x11-terms/rxvt-unicode-9.02-r1'
All wterm users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=x11-terms/wterm-6.2.9-r3'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200805-03 http://bugs.gentoo.org/show_bug.cgi?id=216833
http://bugs.gentoo.org/show_bug.cgi?id=217819
http://bugs.gentoo.org/show_bug.cgi?id=219746
http://bugs.gentoo.org/show_bug.cgi?id=219750
http://bugs.gentoo.org/show_bug.cgi?id=219754
http://bugs.gentoo.org/show_bug.cgi?id=219760
http://bugs.gentoo.org/show_bug.cgi?id=219762
Insight
A vulnerability was found in aterm, Eterm, Mrxvt, multi-aterm, RXVT, rxvt-unicode, and wterm, allowing for local privilege escalation.
Severity
Classification
-
CVE CVE-2008-1142, CVE-2008-1692 -
CVSS Base Score: 6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities