BSD

FreeBSD 14 — freeamp — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — freeamp — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 November 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zinf — potential buffer overflow playlist support Upstream summary: The audio player Zinf is vulnerable to a buffer-overflow bug in the management of the playlist files. Table of contents Symptom […]

Read more
FreeBSD 14 — zinf — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — zinf — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 November 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zinf — potential buffer overflow playlist support Upstream summary: The audio player Zinf is vulnerable to a buffer-overflow bug in the management of the playlist files. Table of contents Symptom […]

Read more
FreeBSD 14 — php55-fileinfo — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php55-fileinfo — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 November 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Upstream summary: The PHP Group reports: Fileinfo: Fixed bug #71527 (Buffer over-write in finfo_open with malformed magic file). mbstring: Fixed bug #71906 (AddressSanitizer: negative-size-param (-1) in […]

Read more
NetBSD 10.0 — python27 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — python27 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2014-1912 CVE-2014-7185 CVE-2016-0772 CVE-2016-5636 CVE-2016-5699 CVE-2017-1000158 CVE-2018-1000030 CVE-2019-9740  +12 more Upstream summary: pkgsrc audit-packages flagged python27<2.7.6nb1 for vulnerability class 'arbitrary-code-execution'. Reference: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1912 Table of contents Symptom & Impact Environment […]

Read more
NetBSD 10.0 — mktemp — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — mktemp — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Upstream summary: pkgsrc audit-packages flagged mktemp<1.6 for vulnerability class 'privilege-escalation'. Reference: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=495193 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary […]

Read more
NetBSD 10.0 — openssh — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — openssh — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: NetBSD advisory NetBSD-SA-2024-002 Related CVEs: CVE-2024-6387 CVE-2002-0639 CVE-2006-0225 CVE-2013-4548 CVE-2021-41617 CVE-2023-38408 CVE-2011-0539 CVE-2008-5161  +12 more Upstream summary: The sshd(8) login grace time expiry message is issued from signal handler context where it is not […]

Read more
NetBSD 10.0 — freeDiameter — vulnerability — patch and remediation guide — diagnosis and fix on NetBSD 10.0

NetBSD 10.0 — freeDiameter — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: NetBSD 10.0 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2020-6098 Upstream summary: pkgsrc audit-packages flagged freeDiameter-[0-9]* for vulnerability class 'denial-of-service'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2020-6098 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis […]

Read more
FreeBSD 14 — shtool — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — shtool — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 November 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: shtool — insecure temporary file creation Upstream summary: A Zataz advisory reports that shtool contains a security flaw which could allow a malicious local user to create or overwrite the […]

Read more
FreeBSD 14 — popfile — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — popfile — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 November 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: popfile file disclosure Upstream summary: John Graham-Cumming reports that certain configurations of POPFile may allow the retrieval of any files with the extensions .gif, .png, .ico, .css, as well as […]

Read more
FreeBSD 14 — zh-openoffice — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — zh-openoffice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 November 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openoffice — DOC document heap overflow vulnerability Related CVEs: CVE-2005-0941 Upstream summary: AD-LAB reports that a heap-based buffer overflow vulnerability exists in OpenOffice's handling of DOC documents. When reading a […]

Read more
CHAT