BSD

FreeBSD 12 — ja-eb — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ja-eb — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: eb — Potential buffer overrun vulnerability Upstream summary: Kazuhiro Ito reports: Potential buffer overrun vulnerability is found in eb/multiplex.c. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 12 — cvs+ipv — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — cvs+ipv — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: cvsbug — race condition Related CVEs: CAN-2005-2693 CVE-2004-0180 CVE-2004-0405 CVE-2004-0414 CVE-2004-0416 CVE-2004-0417 CVE-2004-0418 CVE-2004-0778 Upstream summary: Problem description A temporary file is created, used, deleted, and then re-created with the […]

Read more
FreeBSD 12 — php73-imap — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php73-imap — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php-imap — imap_open allows to run arbitrary shell commands via mailbox parameter Upstream summary: The PHP team reports: imap_open allows to run arbitrary shell commands via mailbox parameter. Table of […]

Read more
FreeBSD 12 — py39-sqlalchemy — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py39-sqlalchemy — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py39-sqlalchemy12 — multiple SQL Injection vulnerabilities Related CVEs: CVE-2019-7164 CVE-2019-7548 Upstream summary: 21k reports: SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. nosecurity reports: […]

Read more
FreeBSD 12 — wordpress-mu — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — wordpress-mu — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wordpress — remote admin password reset vulnerability Related CVEs: CVE-2007-4894 CVE-2008-4107 CVE-2008-5278 CVE-2009-2762 Upstream summary: WordPress reports: A specially crafted URL could be requested that would allow an attacker to […]

Read more
FreeBSD 12 — py25-django-devel — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py25-django-devel — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: django — multiple vulnerabilities Related CVEs: CVE-2008-2302 CVE-2009-3695 CVE-2010-3082 Upstream summary: The Django project reports: Please reference CVE/URL list for details Table of contents Symptom & Impact Environment & Reproduction […]

Read more
FreeBSD 12 — mnogosearch — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mnogosearch — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mnGoSearch buffer overflow in UdmDocToTextBuf() Upstream summary: Jedi/Sector One <[email protected]> reported the following on the full-disclosure list: Every document is stored in multiple parts according to its sections (description, body, […]

Read more
FreeBSD 12 — php5-openssl — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php5-openssl — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php5 — multiple vulnerabilities Related CVEs: CVE-2015-6831 CVE-2015-6832 CVE-2015-6833 Upstream summary: The PHP project reports: Core: Fixed bug #69793 (Remotely triggerable stack exhaustion via recursive method calls). Fixed bug #70121 […]

Read more
FreeBSD 12 — py27-cryptography — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py27-cryptography — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-cryptography — tag forgery vulnerability Related CVEs: CVE-2016-9243 CVE-2018-10903 Upstream summary: The Python Cryptographic Authority (PyCA) project reports: finalize_with_tag() allowed tag truncation by default which can allow tag forgery in […]

Read more
CHAT