FreeBSD : libtremor -- memory corruption (40497e81-fee3-4e54-9d5f-175a5c633b73)

critical Nessus Plugin ID 85640

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

The Mozilla Project reports :

Security researcher regenrecht reported via TippingPoint's Zero Day Initiative the possibility of memory corruption during the decoding of Ogg Vorbis files. This can cause a crash during decoding and has the potential for remote code execution.

Solution

Update the affected package.

See Also

https://bugzilla.mozilla.org/show_bug.cgi?id=719612

https://git.xiph.org/?p=tremor.git;a=commitdiff;h=3daa274

http://www.nessus.org/u?5e3551b8

Plugin Details

Severity: Critical

ID: 85640

File Name: freebsd_pkg_40497e81fee34e549d5f175a5c633b73.nasl

Version: 2.4

Type: local

Published: 8/26/2015

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:libtremor, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 8/25/2015

Vulnerability Publication Date: 1/31/2012

Reference Information

CVE: CVE-2012-0444