BSD

NetBSD 10.0 — py-fonttools — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — py-fonttools — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2023-45139 CVE-2025-66034 Upstream summary: pkgsrc audit-packages flagged py{37,38,39,310,311,312}-fonttools>4.28.2<4.43.0 for vulnerability class 'xml-external-entity-vulnerability'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2023-45139 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
FreeBSD 15 — lzo — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — lzo — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 May 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: LZO — potential buffer overrun when processing malicious input data Related CVEs: CVE-2014-4608 Upstream summary: Markus Franz Xaver Johannes Oberhumer reports, in the package's NEWS file: Fixed a potential integer […]

Read more
FreeBSD 15 — p5-Email-Address-List — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — p5-Email-Address-List — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 May 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-Email-Address-List — DDoS related vulnerability Related CVEs: CVE-2014-1474 CVE-2018-18898 Upstream summary: Best PRactical Solutions reports: 0.06 2019-01-02 – Changes to address CVE-2018-18898 which could allow DDoS-type attacks. Thanks to Lukas […]

Read more
FreeBSD 15 — apache-xml-security-c — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — apache-xml-security-c — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 May 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xml-security-c — crashes on malformed KeyInfo content Related CVEs: CVE-2013-2156 CVE-2013-2210 Upstream summary: The shibboleth project reports: SAML messages, assertions, and metadata all commonly make use of the XML Signature […]

Read more
FreeBSD 15 — ripmime — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — ripmime — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 May 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ripMIME — decoding bug allowing content filter bypass Upstream summary: ripMIME may prematurely terminate decoding Base64 encoded messages when it encounters multiple blank lines or other non-standard Base64 constructs. Virus […]

Read more
FreeBSD 15 — xv-m17n — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — xv-m17n — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 May 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xv — exploitable buffer overflows Upstream summary: In a Bugtraq posting, infamous41md(at)hotpop.com reported: there are at least 5 exploitable buffer and heap overflows in the image handling code. this allows […]

Read more
FreeBSD 15 — phpldapadmin — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — phpldapadmin — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 May 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: phpLDAPadmin — Remote PHP code injection vulnerability Related CVEs: CVE-2006-2016 Upstream summary: EgiX (n0b0d13s at gmail dot com) reports: The $sortby parameter passed to 'masort' function in file lib/functions.php isn't […]

Read more
CHAT