FreeBSD : Piwik -- remote command execution vulnerability (23c8423e-9bff-11e0-8ea2-0019d18c446a)

high Nessus Plugin ID 55395

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

The Piwik security advisory reports :

The Piwik 1.5 release addresses a critical security vulnerability, which affect all Piwik users that have let granted some access to the 'anonymous' user.

Piwik contains a remotely exploitable vulnerability that could allow a remote attacker to execute arbitrary code. Only installations that have granted untrusted view access to their stats (ie. grant 'view' access to a website to anonymous) are at risk.

Solution

Update the affected package.

See Also

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=158084

https://matomo.org/blog/2011/06/piwik-1-5-security-advisory/

http://www.nessus.org/u?f890e3e2

Plugin Details

Severity: High

ID: 55395

File Name: freebsd_pkg_23c8423e9bff11e08ea20019d18c446a.nasl

Version: 1.10

Type: local

Published: 6/22/2011

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:piwik, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 6/21/2011

Vulnerability Publication Date: 6/21/2011