FreeBSD 12

FreeBSD 12 — py35-buildbot — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py35-buildbot — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: buildbot — OAuth Authentication Vulnerability Related CVEs: CVE-2019-12300 CVE-2019-7313 Upstream summary: Buildbot accepted user-submitted authorization token from OAuth and used it to authenticate user. The vulnerability can lead to malicious […]

Read more
FreeBSD 12 — linux-f10-png — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-f10-png — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: png — memory corruption/possible remote code execution Related CVEs: CVE-2011-3048 Upstream summary: The PNG project reports: libpng fails to correctly handle malloc() failures for text chunks (in png_set_text_2()), which can […]

Read more
FreeBSD 12 — sugarcrm — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — sugarcrm — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sugarcrm — multiple vulnerabilities Related CVEs: CVE-2017-14508 CVE-2017-14509 CVE-2017-14510 Upstream summary: sugarcrm developers report: An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and […]

Read more
FreeBSD 12 — fr-cups-base — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — fr-cups-base — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: cups-base — HPGL buffer overflow vulnerability Related CVEs: CVE-2004-1267 Upstream summary: Ariel Berkman has discovered a buffer overflow vulnerability in CUPS's HPGL input driver. This vulnerability could be exploited to […]

Read more
FreeBSD 12 — libFS — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libFS — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xorg — protocol handling issues in X Window System client libraries Related CVEs: CVE-2013-1981 CVE-2013-1982 CVE-2013-1983 CVE-2013-1984 CVE-2013-1985 CVE-2013-1986 CVE-2013-1987 CVE-2013-1988  +12 more Upstream summary: freedesktop.org reports: Ilja van Sprundel, […]

Read more
FreeBSD 12 — apache-event — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — apache-event — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Apache — Insecure LD_LIBRARY_PATH handling Related CVEs: CVE-2011-3192 CVE-2012-0883 Upstream summary: Apache reports: Insecure handling of LD_LIBRARY_PATH was found that could lead to the current working directory to be searched […]

Read more
FreeBSD 12 — linux_base-suse — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux_base-suse — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zlib — buffer overflow vulnerability Related CVEs: CVE-2005-1849 CVE-2005-1920 Upstream summary: Problem description A fixed-size buffer is used in the decompression of data streams. Due to erronous analysis performed when […]

Read more
FreeBSD 12 — mail-notification — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mail-notification — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mail-notification — denial-of-service vulnerability Upstream summary: Caused by an untested return value, and a resulting null pointer dereference, it is possible for an attacker to crash the application. However, the […]

Read more
FreeBSD 12 — xchat — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — xchat — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xchat remotely exploitable buffer overflow (Socks5) Related CVEs: CVE-2004-0409 Upstream summary: A straightforward stack buffer overflow exists in XChat's Socks5 proxy support. The XChat developers report that `tsifra' discovered this […]

Read more
FreeBSD 12 — php56-dom — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php56-dom — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 January 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php5 — multiple vulnerabilities Related CVEs: CVE-2015-4643 CVE-2015-4644 Upstream summary: The PHP project reports: DOM and GD: Fixed bug #69719 (Incorrect handling of paths with NULs). FTP: Improved fix for […]

Read more
CHAT