FreeBSD : seti@home remotely exploitable buffer overflow (0e154a9c-5d7a-11d8-80e3-0020ed76ef5a)

high Nessus Plugin ID 38114

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

The seti@home client contains a buffer overflow in the HTTP response handler. A malicious, spoofed seti@home server can exploit this buffer overflow to cause remote code execution on the client. Exploit programs are widely available.

Solution

Update the affected package.

See Also

http://www.nessus.org/u?760b3d2d

http://www.nessus.org/u?826f4113

http://www.nessus.org/u?29242ccf

Plugin Details

Severity: High

ID: 38114

File Name: freebsd_pkg_0e154a9c5d7a11d880e30020ed76ef5a.nasl

Version: 1.13

Type: local

Published: 4/23/2009

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:setiathome, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2/12/2004

Vulnerability Publication Date: 4/8/2003