FreeBSD : groovy -- remote execution of untrusted code (67b3fef2-2bea-11e5-86ff-14dae9d210b8)

This script is Copyright (C) 2015-2017 Tenable Network Security, Inc.


Synopsis :

The remote FreeBSD host is missing a security-related update.

Description :

Cedric Champeau reports :

Description

When an application has Groovy on the classpath and that it uses
standard Java serialization mechanism to communicate between servers,
or to store local data, it is possible for an attacker to bake a
special serialized object that will execute code directly when
deserialized. All applications which rely on serialization and do not
isolate the code which deserializes objects are subject to this
vulnerability.

See also :

http://seclists.org/oss-sec/2015/q3/121
http://groovy-lang.org/security.html
https://issues.apache.org/jira/browse/GROOVY-7504
http://www.nessus.org/u?d6d1affa

Solution :

Update the affected package.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)

Family: FreeBSD Local Security Checks

Nessus Plugin ID: 84814 ()

Bugtraq ID:

CVE ID: CVE-2015-3253

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now