Summary
The remote host is missing an update as announced
via advisory SSA:2003-237-01.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=SSA:2003-237-01
Insight
Upgraded infozip packages are available for Slackware 9.0 and -current.
These fix a security issue where a specially crafted archive may overwrite files (including system files anywhere on the filesystem) upon extraction by a user with sufficient permissions.
For more information, see:
http://www.securityfocus.com/bid/7550
http://lwn.net/Articles/38540/
http://xforce.iss.net/xforce/xfdb/12004
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0282
Severity
Classification
-
CVE CVE-2003-0282 -
CVSS Base Score: 2.6
AV:N/AC:H/Au:N/C:N/I:P/A:N
Related Vulnerabilities