On Fri, Jan 24, 2003 at 09:20:57AM -0800, Anne Carasik wrote: > This is the message I get: > Warning > unknown (32788/udp) > The statd RPC service is running. This service has a long history of security >holes, so you should really know what you are doing if you decide to let it run. > * NO SECURITY HOLES REGARDING THIS PROGRAM HAVE BEEN TESTED, SO THIS MIGHT BE A >FALSE POSITIVE * > > We suggest that you disable this service. > > Risk factor : High > > CVE_:_CVE-1999-0493
See:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0493
http://www.cert.org/advisories/CA-99-05-statd-automountd.html
http://online.securityfocus.com/bid/450
> I take it you're referring to the CVE #?
Actually, he was referring to the plugin id, which in this case is
10235.
To others... Can plugin ids and/or names be included in all reports? It
would seem a helpful addition.
George
--
[EMAIL PROTECTED]
msg03340/pgp00000.pgp
Description: PGP signature
