This script is Copyright (C) 2006-2013 Tenable Network Security, Inc.
The remote Mandrake Linux host is missing one or more security
Two vulnerabilities in heartbeat prior to 2.0.6 was discovered by Yan
Rong Ge. The first is that heartbeat would set insecure permissions in
an shmget call for shared memory, allowing a local attacker to cause
an unspecified denial of service via unknown vectors (CVE-2006-3815).
The second is a remote vulnerability that could allow allow the master
control process to read invalid memory due to a specially crafted
heartbeat message and die of a SEGV, all prior to any authentication
Updated packages have been patched to correct these issues.
Update the affected packages.
Risk factor :
Medium / CVSS Base Score : 5.0