Summary
The remote host is missing updates announced in
advisory GLSA 201206-26.
Solution
All RPM users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=app-arch/rpm-4.9.1.3'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20201206-26 http://bugs.gentoo.org/show_bug.cgi?id=335880
http://bugs.gentoo.org/show_bug.cgi?id=384967
http://bugs.gentoo.org/show_bug.cgi?id=410949
Insight
Multiple vulnerabilities have been found in RPM, possibly allowing local attackers to gain elevated privileges or remote attackers to execute arbitrary code.
Severity
Classification
-
CVE CVE-2010-2059, CVE-2010-2197, CVE-2010-2198, CVE-2010-2199, CVE-2011-3378, CVE-2012-0060, CVE-2012-0061, CVE-2012-0815 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities