Solution: Update to version 2.2.5 or apply patches (see vendor advisory for more details).
Provided and/or discovered by: Ossi Herrala and Jukka Taimisto from the CROSS project at Codenomicon. Reported via CERT-FI.
Changelog: 2008-05-21: Updated "Solution" section due to an error introduced in version 2.2.4. Updated "Original Advisory" section.
2008-05-30: Added links to US-CERT.
2008-06-02: Added link to US-CERT.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.