Summary
The remote host is missing updates announced in
advisory GLSA 200911-06.
Solution
All PEAR Net_Traceroute users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=dev-php/PEAR-Net_Traceroute-0.21.2'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200911-06 http://bugs.gentoo.org/show_bug.cgi?id=294264
Insight
An input sanitation error in PEAR Net_Traceroute might allow remote attackers to execute arbitrary commands.
Severity
Classification
-
CVE CVE-2009-4025 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities