BSD

FreeBSD 13 — gstreamer1-plugins-ogg — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — gstreamer1-plugins-ogg — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 January 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gstreamer1-plugins-ogg — Out-of-bounds write in Ogg demuxer Related CVEs: CVE-2024-47615 Upstream summary: The GStreamer Security Center reports: An out-of-bounds write in the Ogg demuxer that can cause crashes for certain […]

Read more
NetBSD 10.0 — mutt — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — mutt — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2006-3242 CVE-2014-0467 CVE-2006-5297 CVE-2006-5298 CVE-2007-1558 CVE-2007-2683 CVE-2007-1268 CVE-2018-14349  +12 more Upstream summary: pkgsrc audit-packages flagged mutt<1.2.5.1 for vulnerability class 'remote-user-shell'. Reference: http://www.mutt.org/announce/mutt-1.2.5.1-1.3.25.html Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 14 — mailman-exim4-with-htdig — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mailman-exim4-with-htdig — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mailman < 2.1.38 — CSRF vulnerability of list mod or member against list admin page Related CVEs: CVE-2021-43331 CVE-2021-43332 CVE-2021-44227 Upstream summary: Mark Sapiro reports: A list moderator or list […]

Read more
NetBSD 10.0 — libksba — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — libksba — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2022-3515 CVE-2022-47629 CVE-2006-5111 Upstream summary: pkgsrc audit-packages flagged libksba<1.6.3 for vulnerability class 'remote-code-execution'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2022-3515 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage […]

Read more
FreeBSD 12 — icinga — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — icinga — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 January 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: icinga2 — TLS Certificate Validation Bypass Related CVEs: CVE-2014-2386 CVE-2024-49369 Upstream summary: The Icinga project reports: Icinga is a monitoring system which checks the availability of network resources, notifies users […]

Read more
FreeBSD 14 — opensmtpd — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — opensmtpd — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenSMTPd — LPE and RCE in OpenSMTPD's default install Related CVEs: CVE-2015-7687 CVE-2020-7247 CVE-2020-8793 CVE-2020-8794 Upstream summary: OpenSMTPD developers reports: An out of bounds read in smtpd allows an attacker […]

Read more
NetBSD 10.0 — binutils — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — binutils — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2006-2362 CVE-2017-6966 CVE-2017-12448 CVE-2018-20623 CVE-2020-16592 CVE-2021-37322 CVE-2014-8501 CVE-2014-9939  +12 more Upstream summary: pkgsrc audit-packages flagged binutils<2.16.1 for vulnerability class 'privilege-escalation'. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1704 Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 14 — rubygem18-rack — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rubygem18-rack — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Ruby Rack Gem — Multiple Issues Related CVEs: CVE-2013-0262 CVE-2013-0263 Upstream summary: Rack developers report: Today we are proud to announce the release of Rack 1.4.5. Fix CVE-2013-0263, timing attack […]

Read more
FreeBSD 14 — wu-ftpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — wu-ftpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wu-ftpd — remote globbing DoS vulnerability Related CVEs: CVE-2004-0148 CVE-2005-0256 Upstream summary: An iDEFENSE Security Advisory reports: Remote exploitation of an input validation vulnerability in version 2.6.2 of WU-FPTD could […]

Read more
FreeBSD 14 — openssl-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — openssl-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenSSL — Multiple vulnerabilities Related CVEs: CVE-2016-2177 CVE-2016-2178 CVE-2016-2179 CVE-2016-2180 CVE-2016-2181 CVE-2016-2182 CVE-2016-2183 CVE-2016-6302  +12 more Upstream summary: The OpenSSL project reports: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286) […]

Read more
CHAT