FreeBSD : mkvtoolnix -- code execution via specially crafted files (aeb7874e-8df1-11e6-a082-5404a68ad561)

high Nessus Plugin ID 93934

Language:

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Moritz Bunkus reports :

most of the bugs fixed on 2016-09-06 and 2016-09-07 for issue #1780 are potentially exploitable. The scenario is arbitrary code execution with specially crafted files.

Solution

Update the affected package.

See Also

https://mkvtoolnix.download/doc/NEWS.md

http://www.nessus.org/u?380b484a

Plugin Details

Severity: High

ID: 93934

File Name: freebsd_pkg_aeb7874e8df111e6a0825404a68ad561.nasl

Version: 2.4

Type: local

Published: 10/10/2016

Updated: 1/4/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:mkvtoolnix, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 10/9/2016

Vulnerability Publication Date: 9/7/2016