Common Problems

FreeBSD 12 — py35-borgbackup — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py35-borgbackup — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: borgbackup — remote users can override repository restrictions Related CVEs: CVE-2017-15914 Upstream summary: BorgBackup reports: Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers. […]

Read more
FreeBSD 12 — BitchX — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — BitchX — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: irc/bitchx — multiple vulnerabilities Related CVEs: CVE-2007-4584 CVE-2007-5839 CVE-2007-5922 Upstream summary: bannedit reports: Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a […]

Read more
FreeBSD 12 — hiawatha — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — hiawatha — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: hiawatha — memory leak in PreventSQLi routine Upstream summary: Hugo Leisink reports via private mail to maintainer: The memory leak was introduced in version 7.6. It is in the routing […]

Read more
FreeBSD 12 — potrace — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — potrace — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: potrace — multiple memory failure Related CVEs: CVE-2016-8685 CVE-2016-8686 Upstream summary: potrace reports: CVE-2016-8685: invalid memory access in findnext CVE-2016-8686: memory allocation failure Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 12 — duo — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — duo — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: duo — Two-factor authentication bypass Upstream summary: The duo security team reports: An untrusted user may be able to set the http_proxy variable to an invalid address. If this happens, […]

Read more
FreeBSD 12 — rubygem-geminabox — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rubygem-geminabox — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-geminabox — XSS vulnerabilities Related CVEs: CVE-2017-14506 CVE-2017-14683 CVE-2017-16792 Upstream summary: NVD reports: Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject […]

Read more
FreeBSD 12 — compat5x-amd — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — compat5x-amd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openssl — potential SSL 2.0 rollback Related CVEs: CVE-2005-2969 Upstream summary: Vulnerability: Such applications are affected if they use the option SSL_OP_MSIE_SSLV2_RSA_PADDING. This option is implied by use of SSL_OP_ALL, […]

Read more
Debian 9 — libarchive-zip-perl — vulnerability — patch and remediation guide — diagnosis and fix on Debian 9

Debian 9 — libarchive-zip-perl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 December 2018 Affected versions: Debian 9 (stretch) 📖 ~4 min read  •  Source: Debian Security Tracker Related CVEs: CVE-2018-10860 Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance […]

Read more
SLES 15 — rarpd-s20161105 — vulnerability — patch and remediation guide — diagnosis and fix on SLES 15

SLES 15 — rarpd-s20161105 — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 December 2018 Affected versions: SLES 15 📖 ~4 min read  •  Source: SUSE security advisory (see also SUSE bugzilla) Related CVEs: CVE-2010-2529 Upstream summary: Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of […]

Read more
FreeBSD 12 — mariadb-server — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mariadb-server — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 December 2018 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL – Multiple vulnerabilities Related CVEs: CVE-2012-4414 CVE-2012-5611 CVE-2012-5612 CVE-2012-5615 CVE-2012-5627 CVE-2015-4792 CVE-2015-4802 CVE-2015-4807  +8 more Upstream summary: Oracle reports: Critical Patch Update: MySQL Server, version(s) 5.5.45 and prior, 5.6.26 […]

Read more
CHAT