Common Problems

FreeBSD 12 — icedtea-web — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — icedtea-web — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Several vulnerabilities found in IcedTea-Web Related CVEs: CVE-2012-3422 CVE-2012-3423 Upstream summary: The IcedTea project team reports: CVE-2012-3422: Use of uninitialized instance pointers An uninitialized pointer use flaw was found in […]

Read more
FreeBSD 12 — apr — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — apr — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Apache APR — DoS vulnerabilities Related CVEs: CVE-2009-0023 CVE-2009-1955 CVE-2009-1956 CVE-2009-3560 CVE-2009-3720 CVE-2010-1623 CVE-2011-0419 CVE-2011-1928 Upstream summary: The Apache Portable Runtime Project reports: Reimplement apr_fnmatch() from scratch using a non-recursive […]

Read more
FreeBSD 12 — openwebmail — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — openwebmail — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: "Content-Type" XSS vulnerability affecting other webmail systems Related CVEs: CVE-2004-0519 Upstream summary: Roman Medina-Heigl Hernandez did a survey which other webmail systems where vulnerable to a bug he discovered in […]

Read more
Ubuntu 16.04 — ocaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Ubuntu 16.04

Ubuntu 16.04 — ocaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 December 2018 Affected versions: Ubuntu 16.04 (xenial) 📖 ~4 min read  •  Source: Ubuntu Security Notice USN-4778-1 Related CVEs: CVE-2015-8869 CVE-2018-9838 Upstream summary: It was discovered that OCaml mishandled sign extensions. A remote attacker could use this vulnerability to steal sensitive information, cause a denial of […]

Read more
SLES 15 — argyllcms — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — argyllcms — vulnerability — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2012-1616 Upstream summary: Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause […]

Read more
FreeBSD 12 — linux-c6-expat — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-c6-expat — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: expat — denial of service vulnerability on malformed input Related CVEs: CVE-2016-0718 Upstream summary: Gustavo Grieco reports: The Expat XML parser mishandles certain kinds of malformed input documents, resulting in […]

Read more
FreeBSD 12 — mplayer-gtk — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mplayer-gtk — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mplayer — vulnerability in STR files processor Related CVEs: CVE-2004-0433 CVE-2004-1187 CVE-2004-1188 CVE-2005-1195 CVE-2006-0579 CVE-2006-1502 CVE-2006-6172 CVE-2007-1246  +8 more Upstream summary: Secunia reports: The vulnerability is caused due to a […]

Read more
FreeBSD 12 — py33-cryptography — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py33-cryptography — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-cryptography — vulnerable HKDF key generation Related CVEs: CVE-2016-9243 Upstream summary: Alex Gaynor reports: Fixed a bug where “HKDF“ would return an empty byte-string if used with a “length“ less […]

Read more
FreeBSD 12 — fbsdmon — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — fbsdmon — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fbsdmon — information disclosure vulnerability Upstream summary: Alan Somers reports: The web site used by this port, http://fbsdmon.org, has been taken over by cybersquatters. That means that users are sending […]

Read more
FreeBSD 12 — pine4-ssl — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — pine4-ssl — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pine remotely exploitable buffer overflow in newmail.c Upstream summary: Kris Kennaway reports a remotely exploitable buffer overflow in newmail.c. Mike Silbersack submitted the fix. Table of contents Symptom & Impact […]

Read more
CHAT