FreeBSD : libtremor -- memory corruption (40497e81-fee3-4e54-9d5f-175a5c633b73)

Critical Nessus Plugin ID 85640

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

The Mozilla Project reports :

Security researcher regenrecht reported via TippingPoint's Zero Day Initiative the possibility of memory corruption during the decoding of Ogg Vorbis files. This can cause a crash during decoding and has the potential for remote code execution.

Solution

Update the affected package.

See Also

https://bugzilla.mozilla.org/show_bug.cgi?id=719612

https://git.xiph.org/?p=tremor.git;a=commitdiff;h=3daa274

http://www.nessus.org/u?5e3551b8

Plugin Details

Severity: Critical

ID: 85640

File Name: freebsd_pkg_40497e81fee34e549d5f175a5c633b73.nasl

Version: 2.2

Type: local

Published: 2015/08/26

Updated: 2018/11/10

Dependencies: 12634

Risk Information

Risk Factor: Critical

CVSS v2.0

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:libtremor, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2015/08/25

Vulnerability Publication Date: 2012/01/31

Reference Information

CVE: CVE-2012-0444