The remote host is missing an update to tomboy announced via advisory MDVSA-2008:064.
A flaw in how tomboy handles LD_LIBRARY_PATH was discovered where by appending paths to LD_LIBRARY_PATH the program would also search the current directory for shared libraries. In directories containing network data, those libraries could be injected into the application.
The updated packages have been patched to correct this issue.
Affected: 2007.1, 2008.0
Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.