Renaud,

This is the message I get:
Warning 
unknown (32788/udp)
The statd RPC service is running.  This service has a long history of security holes, 
so you should really know what you are doing if you decide to let it run.  
* NO SECURITY HOLES REGARDING THIS PROGRAM HAVE BEEN TESTED, SO THIS MIGHT BE A FALSE 
POSITIVE *

We suggest that you disable this service.  

Risk factor : High 

CVE_:_CVE-1999-0493

I take it you're referring to the CVE #?

-Anne

Renaud Deraison grabbed a keyboard and typed...
> On Fri, Jan 24, 2003 at 12:45:24AM -0800, Anne Carasik wrote:
> > Hi all,
> > 
> > I keep getting a lot of warnings about statd. Can anyone explain
> > the vulnerability of statd and most importantly: when it was fixed?
> 
> What is the ID of the plugin giving you an error ?
> 

-- 
              .-"".__."``".   Anne Carasik, System Administrator
 .-.--. _...' (/)   (/)   ``'   gator at cacr dot caltech dot edu 
(O/ O) \-'      ` -="""=.    ',  Center for Advanced Computing Research    
~`~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Attachment: msg03337/pgp00000.pgp
Description: PGP signature

Reply via email to