FreeBSD 12

FreeBSD 12 — libraw — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libraw — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 April 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libraw — multiple DoS vulnerabilities Related CVEs: CVE-2015-3885 CVE-2015-8366 CVE-2015-8367 CVE-2017-14265 CVE-2017-14348 CVE-2017-14608 CVE-2017-16909 CVE-2017-16910  +3 more Upstream summary: Secunia Research reports: CVE-2018-5800: An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function […]

Read more
FreeBSD 12 — strongswan — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — strongswan — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 April 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: strongSwan — Heap-based buffer overflow in eap-mschapv2 plugin due to improper handling of failure request packets Related CVEs: CVE-2013-2944 CVE-2013-5018 CVE-2013-6075 CVE-2013-6076 CVE-2014-2338 CVE-2015-3991 CVE-2015-4171 CVE-2015-8023  +12 more Upstream summary: […]

Read more
FreeBSD 12 — bash-static — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — bash-static — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 April 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bash — remote code execution Related CVEs: CVE-2014-6271 CVE-2014-6277 CVE-2014-6278 CVE-2014-7169 CVE-2014-7186 CVE-2014-7187 Upstream summary: Note that this is different than the public "Shellshock" issue. Specially crafted environment variables could […]

Read more
FreeBSD 12 — pkcs11-helper — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — pkcs11-helper — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 April 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pkcs11-helper — deserialize buffer overflow Upstream summary: Alon Bar-Lev reports: util: fix deserialize buffer overflow. thanks to Aarnav Bos. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 12 — iodine — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — iodine — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 April 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: iodined — authentication bypass Upstream summary: Erik Ekman of the iodine project reports: The client could bypass the password check by continuing after getting error from the server and guessing […]

Read more
FreeBSD 12 — percona55-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — percona55-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 April 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL Server — Multiple vulerabilities Related CVEs: CVE-2015-3194 CVE-2015-4792 CVE-2015-4802 CVE-2015-4807 CVE-2015-4815 CVE-2015-4826 CVE-2015-4830 CVE-2015-4836  +12 more Upstream summary: Oracle reports: This Critical Patch Update contains 45 new security patches […]

Read more
FreeBSD 12 — roundcube-thunderbird_labels — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — roundcube-thunderbird_labels — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 April 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: roundcube-thunderbird_labels — RCE with custom label titles Upstream summary: The Roundcube project reports: Description: Remote code execution vulnerability in roundcube-thunderbird_labels when tb_label_modify_labels is enabled. Workaround: If you cannot upgrade to […]

Read more
FreeBSD 12 — libtomcrypt — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libtomcrypt — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 April 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libtomcrypt — weak signature scheme with ECC keys Upstream summary: The Secure Science Corporation reports that libtomcrypt is vulnerable to a weak signature scheme. This allows an attacker to create […]

Read more
FreeBSD 12 — unrtf — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — unrtf — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 April 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: unrtf — buffer overflow vulnerability Related CVEs: CVE-2004-1297 Upstream summary: Yosef Klein and Limin Wang have found a buffer overflow vulnerability in unrtf that can allow an attacker to execute […]

Read more
CHAT