This script is Copyright (C) 2004-2015 Tenable Network Security, Inc.
The remote Gentoo host is missing one or more security-related
The remote host is affected by the vulnerability described in GLSA-200410-01
(sharutils: Buffer overflows in shar.c and unshar.c)
sharutils contains two buffer overflows. Ulf Harnhammar discovered a
buffer overflow in shar.c, where the length of data returned by the wc
command is not checked. Florian Schilhabel discovered another buffer
overflow in unshar.c.
An attacker could exploit these vulnerabilities to execute arbitrary
code as the user running one of the sharutils programs.
There is no known workaround at this time.
See also :
All sharutils users should upgrade to the latest version:
# emerge sync
# emerge -pv '>=app-arch/sharutils-4.2.1-r10'
# emerge '>=app-arch/sharutils-4.2.1-r10'
Risk factor :
High / CVSS Base Score : 7.5