FreeBSD : libarchive -- multiple vulnerabilities (4a0d9b53-395d-11e6-b3c8-14dae9d210b8)

Medium Nessus Plugin ID 91791


The remote FreeBSD host is missing a security-related update.


Hanno Bock and Cisco Talos report :

- Out of bounds heap read in RAR parser

- Signed integer overflow in ISO parser

- TALOS-2016-0152 [CVE-2016-4300]: 7-Zip read_SubStreamsInfo Integer Overflow

- TALOS-2016-0153 [CVE-2016-4301]: mtree parse_device Stack Based Buffer Overflow

- TALOS-2016-0154 [CVE-2016-4302]: Libarchive Rar RestartModel Heap Overflow


Update the affected package.

See Also

Plugin Details

Severity: Medium

ID: 91791

File Name: freebsd_pkg_4a0d9b53395d11e6b3c814dae9d210b8.nasl

Version: 2.6

Type: local

Published: 2016/06/24

Updated: 2018/12/19

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS v3.0

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:libarchive, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 2016/06/23

Vulnerability Publication Date: 2016/06/23

Reference Information

CVE: CVE-2015-8934, CVE-2016-4300, CVE-2016-4301, CVE-2016-4302