This script is Copyright (C) 2014-2015 Tenable Network Security, Inc.
The remote Gentoo host is missing one or more security-related
The remote host is affected by the vulnerability described in GLSA-201412-21
(mod_wsgi: Privilege escalation)
Two vulnerabilities have been found in mod_wsgi:
Error codes returned by setuid are not properly handled
A memory leak exists via the “Content-Type” header
A local attacker may be able to gain escalated privileges. Furthermore,
a remote attacker may be able to obtain sensitive information.
There is no known workaround at this time.
See also :
All mod_wsgi users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=www-apache/mod_wsgi-3.5'
Risk factor :
Medium / CVSS Base Score : 6.2
CVSS Temporal Score : 5.4
Public Exploit Available : true