FreeBSD : dnsmasq -- remotely exploitable buffer overflow in release candidate (7927165a-0126-11e5-9d98-080027ef73ec)

high Nessus Plugin ID 83797

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Simon Kelley reports :

Anyone running 2.[73]rc6 or 2.[73]rc7 should be aware that there's a remotely exploitable buffer overflow in those trees. I just tagged 2.[73]rc8, which includes the fix.

(Corrections from second URL.)

Solution

Update the affected package.

See Also

http://www.nessus.org/u?ddf545e2

http://www.nessus.org/u?e4c8b496

http://www.nessus.org/u?a4a089c6

Plugin Details

Severity: High

ID: 83797

File Name: freebsd_pkg_7927165a012611e59d98080027ef73ec.nasl

Version: 2.4

Type: local

Published: 5/26/2015

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:dnsmasq-devel, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 5/23/2015

Vulnerability Publication Date: 5/15/2015