On Fri, Jan 24, 2003 at 09:20:57AM -0800, Anne Carasik wrote:

> This is the message I get:
> Warning 
> unknown (32788/udp)
> The statd RPC service is running.  This service has a long history of security 
>holes, so you should really know what you are doing if you decide to let it run.  
> * NO SECURITY HOLES REGARDING THIS PROGRAM HAVE BEEN TESTED, SO THIS MIGHT BE A 
>FALSE POSITIVE *
> 
> We suggest that you disable this service.  
> 
> Risk factor : High 
> 
> CVE_:_CVE-1999-0493

See:
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0493
    http://www.cert.org/advisories/CA-99-05-statd-automountd.html
    http://online.securityfocus.com/bid/450

> I take it you're referring to the CVE #?

Actually, he was referring to the plugin id, which in this case is
10235. 

To others...  Can plugin ids and/or names be included in all reports? It
would seem a helpful addition. 

George
-- 
[EMAIL PROTECTED]

Attachment: msg03340/pgp00000.pgp
Description: PGP signature

Reply via email to