2025 - Page 966 of 1252

FreeBSD 14 — kea — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — kea — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 March 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ISC KEA — Invalid characters cause assert Related CVEs: CVE-2015-8373 CVE-2019-6472 CVE-2019-6473 CVE-2019-6474 CVE-2025-11232 CVE-2025-32801 CVE-2025-32802 CVE-2025-32803  +1 more Upstream summary: Internet Systems Consortium, Inc. reports: To trigger the issue, […]

Read more
NetBSD 10.0 — openafs — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — openafs — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2018-16947 CVE-2014-0159 CVE-2014-4044 CVE-2016-9772 CVE-2017-17432 CVE-2018-16948 CVE-2018-16949 CVE-2019-18601  +2 more Upstream summary: pkgsrc audit-packages flagged openafs<1.4.4 for vulnerability class 'privilege-escalation'. Reference: http://www.openafs.org/security/OPENAFS-SA-2007-001.txt Table of contents Symptom & Impact Environment […]

Read more
NetBSD 10.0 — grub2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — grub2 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2020-15706 CVE-2020-25632 CVE-2020-25647 CVE-2022-3775 CVE-2022-28736 CVE-2022-28735 CVE-2025-0622 CVE-2015-8370  +12 more Upstream summary: pkgsrc audit-packages flagged grub2<2.0.6 for vulnerability class 'use-after-free'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2020-15706 Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 14 — rubygem18-activemodel — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rubygem18-activemodel — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 March 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Ruby Activemodel Gem — Circumvention of attr_protected Related CVEs: CVE-2013-0276 Upstream summary: Aaron Patterson reports: The attr_protected method allows developers to specify a blacklist of model attributes which users should […]

Read more
AlmaLinux 9 — toolbox — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on AlmaLinux 9

AlmaLinux 9 — toolbox — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 9 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2025:13673 Related CVEs: CVE-2025-23266 CVE-2023-45290 CVE-2024-24785 CVE-2024-24788 CVE-2024-24791 CVE-2023-39318 CVE-2023-39319 CVE-2023-39326  +12 more Upstream summary: Toolbox is a tool for Linux operating systems, which allows the use of containerized command line environments. […]

Read more
FreeBSD 14 — pl-openoffice — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — pl-openoffice — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 March 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openoffice — DOC document heap overflow vulnerability Related CVEs: CVE-2004-0752 CVE-2005-0941 Upstream summary: AD-LAB reports that a heap-based buffer overflow vulnerability exists in OpenOffice's handling of DOC documents. When reading […]

Read more
NetBSD 10.0 — courier-mta — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — courier-mta — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2021-38084 CVE-2006-2659 Upstream summary: pkgsrc audit-packages flagged courier-mta<1.1.5 for vulnerability class 'remote-code-execution'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2021-38084 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
Ubuntu 20.04 — pcl — vulnerability — patch and remediation guide — diagnosis and fix on Ubuntu 20.04

Ubuntu 20.04 — pcl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 March 2025 Affected versions: Ubuntu 20.04 (focal) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7227-1 Related CVEs: CVE-2024-53432 Upstream summary: It was discovered that PCL incorrectly handled certain malformed files. If a user or automated system were tricked into opening a specially crafted file, […]

Read more
Amazon Linux 2023 — libreswan — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — libreswan — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2024-621 Related CVEs: CVE-2024-3652 CVE-2024-2357 Upstream summary: The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer […]

Read more
Ubuntu 24.04 — proftpd-dfsg — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 24.04

Ubuntu 24.04 — proftpd-dfsg — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 March 2025 Affected versions: Ubuntu 24.04 (noble) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-7297-1 Related CVEs: CVE-2023-48795 CVE-2023-51713 CVE-2024-48651 Upstream summary: Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that the transport protocol implementation in ProFTPD had weak integrity checks. An attacker could […]

Read more
CHAT