BSD

FreeBSD 12 — owncloudclient — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — owncloudclient — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: owncloudclient — Improper validation of certificates when using self-signed certificates Related CVEs: CVE-2015-7298 Upstream summary: owncloud.org reports: The ownCloud Desktop Client was vulnerable against MITM attacks until version 2.0.0 in […]

Read more
FreeBSD 12 — php70-mbstring — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php70-mbstring — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: oniguruma — multiple vulnerabilities Related CVEs: CVE-2015-8874 CVE-2016-5766 CVE-2016-5767 CVE-2016-5768 CVE-2016-5769 CVE-2016-5770 CVE-2016-5771 CVE-2016-5772  +5 more Upstream summary: the PHP project reports: A stack out-of-bounds read occurs in match_at() during […]

Read more
FreeBSD 12 — zoo — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — zoo — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zoo — stack based buffer overflow Related CVEs: CVE-2006-0855 Upstream summary: Jean-Sébastien Guay-Leroux report a vulnerability within the zoo archiver. The vulnerability which is present in the fullpath() function (from […]

Read more
FreeBSD 12 — linux-netscape-navigator — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-netscape-navigator — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libpng stack-based buffer overflow and other code concerns Related CVEs: CVE-2004-0597 CVE-2004-0598 CVE-2004-0599 Upstream summary: Chris Evans has discovered multiple vulnerabilities in libpng, which can be exploited by malicious people […]

Read more
FreeBSD 12 — zh-irssi — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — zh-irssi — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: irssi — heap corruption and missing boundary checks Related CVEs: CVE-2010-1155 CVE-2010-1156 CVE-2016-7044 CVE-2016-7045 Upstream summary: Irssi reports: Remote crash and heap corruption. Remote code execution seems difficult since only […]

Read more
FreeBSD 12 — mozilla-gtk — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mozilla-gtk — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: firefox & mozilla — multiple vulnerabilities Related CVEs: CVE-2004-0597 CVE-2004-0598 CVE-2004-0599 CVE-2004-0717 CVE-2004-0718 CVE-2004-0721 CVE-2004-0722 CVE-2004-0758  +12 more Upstream summary: A Mozilla Foundation Security Advisory reports of multiple issues: Heap […]

Read more
FreeBSD 12 — zabbix — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — zabbix — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zabbix — php frontend multiple vulnerabilities Upstream summary: Secunia reports: Some vulnerabilities have been reported in the ZABBIX PHP frontend, which can be exploited by malicious people to conduct cross-site […]

Read more
FreeBSD 12 — jftpgw — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — jftpgw — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Arbitrary code execution via a format string vulnerability in jftpgw Related CVEs: CVE-2004-0448 Upstream summary: The log functions in jftpgw may allow remotely authenticated user to execute arbitrary code via […]

Read more
FreeBSD 12 — linux-c7-nss — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-c7-nss — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: nss — Use-after-free in TLS 1.2 generating handshake hashes Related CVEs: CVE-2016-2834 CVE-2017-5461 CVE-2017-5462 CVE-2017-7805 Upstream summary: Mozilla reports: During TLS 1.2 exchanges, handshake hashes are generated which point to […]

Read more
FreeBSD 12 — accountsservice — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — accountsservice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: AccountsService — Insufficient path check in user_change_icon_file_authorized_cb() Related CVEs: CVE-2018-14036 Upstream summary: NVD reports: Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check […]

Read more
CHAT