FreeBSD : tin -- buffer overflow vulnerabilities (19a92df1-548d-11db-8f1a-000a48049292)

high Nessus Plugin ID 22515

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Urs Janssen and Aleksey Salow report possible buffer overflows in tin versions 1.8.0 and 1.8.1.

OpenPKG project elaborates there is an allocation off-by-one bug in version 1.8.0 which can lead to a buffer overflow.

Solution

Update the affected packages.

See Also

ftp://ftp.tin.org/pub/news/clients/tin/stable/CHANGES

http://www.nessus.org/u?48a7da07

http://www.nessus.org/u?081b9f79

Plugin Details

Severity: High

ID: 22515

File Name: freebsd_pkg_19a92df1548d11db8f1a000a48049292.nasl

Version: 1.13

Type: local

Published: 10/10/2006

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:tin, p-cpe:/a:freebsd:freebsd:zh-tin, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 10/5/2006

Vulnerability Publication Date: 2/15/2006