The remote host is missing an update to xmcd announced via advisory DSA 1086-1. The xmcdconfig creates directories world-writeable allowing local users to fill the /usr and /var partition and hence cause a denial of service. This problem has been half-fixed since version 2.3-1. For the old stable distribution (woody) this problem has been fixed in version 2.6-14woody1.
For the stable distribution (sarge) this problem has been fixed in version 2.6-17sarge1. For the unstable distribution (sid) this problem has been fixed in version 2.6-18. We recommend that you upgrade your xmcd package. https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201086-1
- Debian Security Advisory DSA 1808-1 (drupal6)
- Debian Security Advisory DSA 1047-1 (resmgr)
- Debian Security Advisory DSA 2650-2 (libvirt - files and device nodes ownership change to kvm group)
- Debian Security Advisory DSA 2731-1 (libgcrypt11 - information leak)
- Debian Security Advisory DSA 1326-1 (fireflier-server)