BSD

FreeBSD 12 — vim+ruby — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — vim+ruby — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: vim — vulnerabilities in modeline handling: glob, expand Related CVEs: CVE-2004-1138 CVE-2005-2368 Upstream summary: Georgi Guninski discovered a way to construct Vim modelines that execute arbitrary shell commands. The vulnerability […]

Read more
FreeBSD 12 — libotr — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libotr — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libotr — integer overflow Related CVEs: CVE-2012-3461 CVE-2016-2851 Upstream summary: X41 D-Sec reports: A remote attacker may crash or execute arbitrary code in libotr by sending large OTR messages. Table […]

Read more
FreeBSD 12 — p5-HTML-Parser — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — p5-HTML-Parser — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-HTML-Parser — denial of service Related CVEs: CVE-2009-3627 Upstream summary: CVE reports: The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service […]

Read more
FreeBSD 12 — findutils — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — findutils — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: findutils — GNU locate heap buffer overrun Related CVEs: CVE-2007-2452 Upstream summary: James Youngman reports: When GNU locate reads filenames from an old-format locate database, they are read into a […]

Read more
FreeBSD 12 — codeigniter — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — codeigniter — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: codeigniter — input validation bypass Upstream summary: The CodeIgniter changelog reports: Security: Fixed a potential object injection in Cache Library 'apc' driver when save() is used with $raw = TRUE. […]

Read more
FreeBSD 12 — php56-xml — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php56-xml — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2016-3074 Upstream summary: The PHP Group reports: BCMath: Fixed bug #72093 (bcpowmod accepts negative scale and corrupts _one_ definition). Exif: Fixed bug #72094 (Out […]

Read more
FreeBSD 12 — vim-gnome — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — vim-gnome — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: vim — multiple vulnerabilities in the netrw module Related CVEs: CVE-2008-3076 Upstream summary: Jan Minar reports: Applying the “D'' to a file with a crafted file name, or inside a […]

Read more
FreeBSD 12 — hanemacs — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — hanemacs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: emacs — movemail format string vulnerability Related CVEs: CVE-2005-0100 Upstream summary: Max Vozeler discovered several format string vulnerabilities in the movemail utility of Emacs. They can be exploited when connecting […]

Read more
FreeBSD 12 — rubygem-activeresource — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rubygem-activeresource — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rails — multiple vulnerabilities Related CVEs: CVE-2013-4491 CVE-2013-6414 CVE-2013-6415 CVE-2013-6416 CVE-2013-6417 Upstream summary: Rails weblog: Rails 3.2.16 and 4.0.2 have been released! These two releases contain important security fixes, so […]

Read more
FreeBSD 12 — tidy-lib — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — tidy-lib — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tidy — heap-buffer-overflow Related CVEs: CVE-2015-5522 CVE-2015-5523 Upstream summary: Geoff McLane reports: tidy is affected by a write out of bounds when processing malformed html files. This issue could be […]

Read more
CHAT