| Description: | The remote host is missing an update to cpio announced via advisory USN-650-1.
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS Ubuntu 7.04 Ubuntu 7.10
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
A buffer overflow was discovered in cpio. If a user were tricked into opening a crafted cpio archive, an attacker could cause a denial of service via application crash, or possibly execute code with the privileges of the user invoking the program. (CVE-2007-4476)
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS: cpio 2.6-10ubuntu0.3
Ubuntu 7.04: cpio 2.6-17ubuntu0.7.04.1
Ubuntu 7.10: cpio 2.8-1ubuntu2.2
In general, a standard system upgrade is sufficient to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-650-1
Risk factor : High |