BSD

FreeBSD 12 — telepathy-gabble — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — telepathy-gabble — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: telepathy-gabble — TLS verification bypass Related CVEs: CVE-2013-1431 Upstream summary: Simon McVittie reports: This release fixes a man-in-the-middle attack. If you use an unencrypted connection to a "legacy Jabber" (pre-XMPP) […]

Read more
FreeBSD 12 — p5-Dancer — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — p5-Dancer — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-Dancer — possible to abuse session cookie values Upstream summary: Russell Jenkins reports: It was possible to abuse session cookie values so that file-based session stores such as Dancer::Session::YAML or […]

Read more
FreeBSD 12 — mysql81-client — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mysql81-client — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL — Multiple vulnerabilities Upstream summary: Oracle reports: 36 new security patches for Oracle MySQL. 11 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over […]

Read more
FreeBSD 12 — inn — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — inn — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: inn — plaintext command injection into encrypted channel Related CVEs: CVE-2011-0411 CVE-2012-3523 Upstream summary: INN developers report: Fixed a possible plaintext command injection during the negotiation of a TLS layer. […]

Read more
FreeBSD 12 — charybdis — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — charybdis — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ircd-ratbox and charybdis — remote DoS vulnerability Upstream summary: atheme.org reports: All versions of Charybdis are vulnerable to a remotely-triggered crash bug caused by code originating from ircd-ratbox 2.0. (Incidentally, […]

Read more
FreeBSD 12 — tin — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — tin — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tin — buffer overflow vulnerabilities Upstream summary: Urs Janssen and Aleksey Salow report possible buffer overflows in tin versions 1.8.0 and 1.8.1. OpenPKG project elaborates there is an allocation off-by-one […]

Read more
FreeBSD 12 — py27-buildbot — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py27-buildbot — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: buildbot — OAuth Authentication Vulnerability Related CVEs: CVE-2019-12300 CVE-2019-7313 Upstream summary: Buildbot accepted user-submitted authorization token from OAuth and used it to authenticate user. The vulnerability can lead to malicious […]

Read more
FreeBSD 12 — mariadb101-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mariadb101-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL Server — Multiple vulerabilities Related CVEs: CVE-2015-3194 CVE-2016-0639 CVE-2016-0640 CVE-2016-0641 CVE-2016-0642 CVE-2016-0643 CVE-2016-0644 CVE-2016-0646  +12 more Upstream summary: Oracle reports: This Critical Patch Update contains 45 new security patches […]

Read more
FreeBSD 12 — metamail — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — metamail — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: metamail format string bugs and buffer overflows Related CVEs: CVE-2004-0104 CVE-2004-0105 Upstream summary: Ulf Härnhammar reported four bugs in metamail: two are format string bugs and two are buffer overflows. […]

Read more
FreeBSD 12 — file — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — file — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: file — Heap buffer overflow possible Related CVEs: CVE-2007-1536 CVE-2014-1943 CVE-2014-2270 CVE-2014-3710 CVE-2014-8116 CVE-2014-8117 Upstream summary: mitre reports cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number […]

Read more
CHAT