FreeBSD : glibc -- gethostbyname buffer overflow (0765de84-a6c1-11e4-a0c1-c485083ca99c) (GHOST)

high Nessus Plugin ID 81062

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Robert Kratky reports :

GHOST is a 'buffer overflow' bug affecting the gethostbyname() and gethostbyname2() function calls in the glibc library. This vulnerability allows a remote attacker that is able to make an application call to either of these functions to execute arbitrary code with the permissions of the user running the application. The gethostbyname() function calls are used for DNS resolving, which is a very common event. To exploit this vulnerability, an attacker must trigger a buffer overflow by supplying an invalid hostname argument to an application that performs a DNS resolution.

Solution

Update the affected packages.

See Also

https://access.redhat.com/articles/1332213

https://www.openwall.com/lists/oss-security/2015/01/27/9

http://www.nessus.org/u?cd7b81d9

Plugin Details

Severity: High

ID: 81062

File Name: freebsd_pkg_0765de84a6c111e4a0c1c485083ca99c.nasl

Version: 1.17

Type: local

Published: 1/29/2015

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.9

CVSS v2

Risk Factor: High

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:linux_base-c6, p-cpe:/a:freebsd:freebsd:linux-f10-devtools, p-cpe:/a:freebsd:freebsd:linux_base-f10, cpe:/o:freebsd:freebsd, p-cpe:/a:freebsd:freebsd:linux-c6-devtools

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/28/2015

Vulnerability Publication Date: 1/27/2015

Exploitable With

Core Impact

Metasploit (Exim GHOST (glibc gethostbyname) Buffer Overflow)

Reference Information

CVE: CVE-2015-0235