BSD

NetBSD 9.4 — kea — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — kea — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2025-32801 CVE-2025-32802 CVE-2025-32803 CVE-2025-40779 CVE-2025-11232 Upstream summary: pkgsrc audit-packages flagged kea<2.6.3 for vulnerability class 'privilege-escalation'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-32801 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
NetBSD 10.0 — apache-2.0.3[0-9]* — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — apache — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Upstream summary: pkgsrc audit-packages flagged apache for vulnerability class 'denial-of-service'. Reference: http://www.apacheweek.com/issues/02-09-27#apache2042 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary […]

Read more
FreeBSD 14 — libwasmtime — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — libwasmtime — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libwasmtime — host panic with fd_renumber WASIp1 function Related CVEs: CVE-2025-53901 Upstream summary: WasmTime development team reports: A bug in Wasmtime's implementation of the WASIp1 set of import functions can […]

Read more
FreeBSD 14 — sylpheed — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — sylpheed — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: claws-mail — POP3 Format String Vulnerability Related CVEs: CVE-2005-0667 CVE-2005-0926 CVE-2007-2958 Upstream summary: A Secunia Advisory reports: A format string error in the "inc_put_error()" function in src/inc.c when displaying a […]

Read more
NetBSD 10.0 — openjdk7 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — openjdk7 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2013-5772 CVE-2013-5802 CVE-2014-0411 CVE-2014-0429 CVE-2014-0446 CVE-2014-0448 CVE-2014-0449 CVE-2014-0451  +12 more Upstream summary: pkgsrc audit-packages flagged openjdk7<1.7.3 for vulnerability class 'multiple-vulnerabilities'. Reference: http://secunia.com/advisories/48009/ Table of contents Symptom & Impact Environment […]

Read more
NetBSD 10.0 — graphite2 — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — graphite2 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2018-7999 Upstream summary: pkgsrc audit-packages flagged graphite2<1.3.5 for vulnerability class 'arbitrary-code-execution'. Reference: http://blog.talosintel.com/2016/02/vulnerability-spotlight-libgraphite.html Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis […]

Read more
FreeBSD 13 — py311-Jinja — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py311-Jinja — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 January 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Jinja2 — Sandbox breakout through attr filter selecting format method Related CVEs: CVE-2024-34064 CVE-2025-27516 Upstream summary: [email protected] reports: Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in […]

Read more
FreeBSD 14 — qpress — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — qpress — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: qpress — directory traversal Related CVEs: CVE-2022-45866 Upstream summary: [email protected] reports: qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal […]

Read more
NetBSD 10.0 — gcvs — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — gcvs — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Upstream summary: pkgsrc audit-packages flagged gcvs<1.0nb2 for vulnerability class 'local-privilege-escalation'. Reference: http://secunia.com/advisories/16553/ Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary […]

Read more
NetBSD 10.0 — ffmpeg — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — ffmpeg — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2009-4631 CVE-2009-4633 CVE-2009-4634 CVE-2009-4635 CVE-2009-4637 CVE-2009-4638 CVE-2009-4640 CVE-2010-3429  +12 more Upstream summary: pkgsrc audit-packages flagged ffmpeg<0.4.9pre1nb4 for vulnerability class 'remote-code-execution'. Reference: https://roundup.mplayerhq.hu/roundup/ffmpeg/issue311 Table of contents Symptom & Impact Environment […]

Read more
CHAT