BSD

FreeBSD 12 — php5-pgsql — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php5-pgsql — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php5 — multiple vulnerabilities Related CVEs: CVE-2015-4643 CVE-2015-4644 Upstream summary: The PHP project reports: DOM and GD: Fixed bug #69719 (Incorrect handling of paths with NULs). FTP: Improved fix for […]

Read more
FreeBSD 12 — ipsec-tools — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ipsec-tools — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ipsec-tools — remotely exploitable computational-complexity attack Related CVEs: CVE-2008-3651 CVE-2008-3652 CVE-2016-10396 Upstream summary: Robert Foggia via NetBSD GNATS reports: The ipsec-tools racoon daemon contains a remotely exploitable computational complexity attack […]

Read more
FreeBSD 12 — quagga-re — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — quagga-re — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: quagga — BGP OPEN denial of service vulnerability Related CVEs: CVE-2012-0249 CVE-2012-0250 CVE-2012-0255 CVE-2012-1820 Upstream summary: CERT reports: If a pre-configured BGP peer sends a specially-crafted OPEN message with a […]

Read more
FreeBSD 12 — vinyl — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — vinyl — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 March 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Vinyl/Varnish — HTTP/2 parsing deficiency Upstream summary: Vinyl Development Team reports: A deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which […]

Read more
FreeBSD 12 — p5-Email-Address-List — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — p5-Email-Address-List — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 March 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-Email-Address-List — DDoS related vulnerability Related CVEs: CVE-2014-1474 CVE-2018-18898 Upstream summary: Best PRactical Solutions reports: 0.06 2019-01-02 – Changes to address CVE-2018-18898 which could allow DDoS-type attacks. Thanks to Lukas […]

Read more
FreeBSD 12 — el-openoffice — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — el-openoffice — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 March 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openoffice — DOC document heap overflow vulnerability Related CVEs: CVE-2004-0752 CVE-2005-0941 Upstream summary: AD-LAB reports that a heap-based buffer overflow vulnerability exists in OpenOffice's handling of DOC documents. When reading […]

Read more
FreeBSD 12 — opendkim — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — opendkim — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 March 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: DomainKeys Identified Mail (DKIM) Verifiers may inappropriately convey message trust Upstream summary: US-CERT reports: DomainKeys Identified Mail (DKIM) Verifiers may inappropriately convey message trust when messages are signed using test […]

Read more
FreeBSD 12 — openjpeg — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — openjpeg — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 March 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenJPEG — integer overflow Related CVEs: CVE-2012-3358 CVE-2012-3535 CVE-2013-1447 CVE-2013-4289 CVE-2013-4290 CVE-2013-6045 CVE-2013-6052 CVE-2013-6053  +9 more Upstream summary: NVD reports: In OpenJPEG 2.3.0, there is an integer overflow vulnerability in […]

Read more
FreeBSD 12 — tla — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — tla — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 March 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: neon format string vulnerabilities Related CVEs: CVE-2004-0179 Upstream summary: Greuff reports that the neon WebDAV client library contains several format string bugs within error reporting code. A malicious server may […]

Read more
FreeBSD 12 — ghostscript9-base — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ghostscript9-base — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 March 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ghostscript — denial of service (crash) via crafted Postscript files Related CVEs: CVE-2015-3228 Upstream summary: MITRE reports: Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier […]

Read more
CHAT