November 2024 - Page 68 of 93

NetBSD 9.4 — dosbox — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — dosbox — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2019-12594 CVE-2019-7165 Upstream summary: pkgsrc audit-packages flagged dosbox<0.74.3 for vulnerability class 'arbitrary-code-execution'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2019-12594 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
Alpine Linux 3.18 — qpdf — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on Alpine Linux 3.18

Alpine Linux 3.18 — qpdf — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Alpine Linux 3.18 / fixed in 7.0.0-r0 📖 ~4 min read  •  Source: Alpine secdb entry — qpdf 7.0.0-r0 Related CVEs: CVE-2017-9208 CVE-2017-9209 CVE-2017-9210 CVE-2017-11624 CVE-2017-11625 CVE-2017-11626 CVE-2017-11627 CVE-2017-12595 Upstream summary: Alpine community repository for vv3.18 ships qpdf 7.0.0-r0 which addresses CVE-2017-9208. […]

Read more
openSUSE Leap 15.5 — ucode-intel — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on openSUSE Leap 15.5

openSUSE Leap 15.5 — ucode-intel — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: openSUSE Leap 15.5 📖 ~4 min read  •  Source: SUSE advisory openSUSE-SU-2024:14496-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-21820 CVE-2024-21853 CVE-2024-23918 CVE-2023-42667 CVE-2023-49141 CVE-2024-24853 CVE-2024-24980 CVE-2024-25939  +12 more Upstream summary: Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when […]

Read more
FreeBSD 14 — bmon — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — bmon — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bmon — unsafe set-user-ID application Upstream summary: Jon Nistor reported that the FreeBSD port of bmon was installed set-user-ID root, and executes commands using relative paths. This could allow local […]

Read more
FreeBSD 12 — php81-composer — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php81-composer — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Composer — Multiple command injections via malicious git/hg branch names Related CVEs: CVE-2022-24828 CVE-2023-43655 CVE-2024-24821 CVE-2024-35241 CVE-2024-35242 Upstream summary: Composer project reports: The status, reinstall and remove commands with packages […]

Read more
FreeBSD 14 — gcpio — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — gcpio — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: GNU cpio — multiple vulnerabilities Related CVEs: CVE-2014-9112 CVE-2015-1197 CVE-2016-2037 CVE-2019-14866 Upstream summary: Sergey Poznyakoff reports: This stable release fixes several potential vulnerabilities CVE-2015-1197: cpio, when using the –no-absolute-filenames option, […]

Read more
FreeBSD 14 — quassel — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — quassel — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: quassel — multiple vulnerabilities Related CVEs: CVE-2013-4422 CVE-2015-3427 CVE-2015-8547 CVE-2016-4414 Upstream summary: Gentoo reports: quasselcore: corruption of heap metadata caused by qdatastream leading to preauth remote code execution. Severity: high, […]

Read more
FreeBSD 14 — py310-treq — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py310-treq — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-treq — sensitive information leak vulnerability Related CVEs: CVE-2022-23607 Upstream summary: Treq's request methods (`treq.get`, `treq.post`, `HTTPClient.request`, `HTTPClient.get`, etc.) accept cookies as a dictionary. Such cookies are not bound to […]

Read more
FreeBSD 14 — ioquake — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ioquake — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: id Tech 3 — remote code execution vulnerability Related CVEs: CVE-2017-6903 Upstream summary: The content auto-download of id Tech 3 can be used to deliver maliciously crafted content, that triggers […]

Read more
CHAT