FreeBSD 12

FreeBSD 12 — caml-light — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — caml-light — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: caml-light — insecure use of temporary files Related CVEs: CVE-2011-4119 Upstream summary: caml-light uses mktemp() insecurely, and also does unsafe things in /tmp during make install. Table of contents Symptom […]

Read more
FreeBSD 12 — libproxy-kde — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libproxy-kde — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libproxy — stack-based buffer overflow Related CVEs: CVE-2012-4504 Upstream summary: Tomas Hoger reports: A buffer overflow flaw was discovered in the libproxy's url::get_pac() used to download proxy.pac proxy auto-configuration file. […]

Read more
FreeBSD 12 — lukemftpd — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — lukemftpd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tnftpd — remotely exploitable vulnerability Related CVEs: CVE-2004-0794 Upstream summary: lukemftpd(8) is an enhanced BSD FTP server produced within the NetBSD project. The sources for lukemftpd are shipped with some […]

Read more
FreeBSD 12 — fcron — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — fcron — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 8 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fcron — multiple vulnerabilities Related CVEs: CVE-2004-1030 CVE-2004-1031 CVE-2004-1032 CVE-2004-1033 Upstream summary: An iDEFENSE Security Advisory states: Multiple vulnerabilities have been found in Fcron. File contents disclosure Configuration Bypass Vulnerability […]

Read more
FreeBSD 12 — libXdmcp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libXdmcp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libXdmcp — insufficient entropy generating session keys Related CVEs: CVE-2017-2625 Upstream summary: The freedesktop and x.org project reports: It was discovered that libXdmcp before 1.1.3 used weak entropy to generate […]

Read more
FreeBSD 12 — pear-XML_RPC — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — pear-XML_RPC — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pear-XML_RPC — remote PHP code injection vulnerability Related CVEs: CVE-2005-1921 CVE-2005-2498 Upstream summary: A Hardened-PHP Project Security Advisory reports: When the library parses XMLRPC requests/responses, it constructs a string of […]

Read more
FreeBSD 12 — dante — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — dante — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fd_set — bitmap index overflow in multiple applications Upstream summary: 3APA3A reports: If programmer fails to check socket number before using select() or fd_set macros, it's possible to overwrite memory […]

Read more
FreeBSD 12 — kdebase — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — kdebase — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: KDM — local privilege escalation vulnerability Related CVEs: CVE-2004-0717 CVE-2004-0718 CVE-2004-0721 CVE-2004-1156 CVE-2004-1157 CVE-2004-1158 CVE-2004-1160 CVE-2004-1171  +6 more Upstream summary: KDE Security Advisory reports: KDM contains a race condition that […]

Read more
FreeBSD 12 — wesnoth — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — wesnoth — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wesnoth — Code Injection vulnerability Related CVEs: CVE-2015-0844 CVE-2015-5069 CVE-2015-5070 CVE-2018-1999023 Upstream summary: shadowm reports: A severe bug was found in the game client which could allow a malicious user […]

Read more
FreeBSD 12 — yahoo-ui — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — yahoo-ui — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: YUI JavaScript library — JavaScript injection exploits in Flash components Related CVEs: CVE-2010-4207 CVE-2010-4208 CVE-2010-4209 CVE-2012-5881 CVE-2012-5882 Upstream summary: The YUI team reports: Vulnerability in YUI 2.4.0 through YUI 2.9.0 […]

Read more
CHAT