FreeBSD 12

FreeBSD 12 — php80-composer — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php80-composer — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 July 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Remote Code Execution via web-accessible composer Related CVEs: CVE-2022-24828 CVE-2023-43655 Upstream summary: Composer project reports: Description: Users publishing a composer.phar to a public web-accessible server where the composer.phar can be […]

Read more
FreeBSD 12 — nebula — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — nebula — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 July 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: nebula — security fix for terrapin vulnerability Related CVEs: CVE-2023-48795 Upstream summary: Upstream reports: Security fix: Update golang.org/x/crypto, which includes a fix for CVE-2023-48795. Table of contents Symptom & Impact […]

Read more
FreeBSD 12 — zookeeper — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — zookeeper — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 June 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: apache — Apache ZooKeeper: Authorization bypass in SASL Quorum Peer Authentication Related CVEs: CVE-2017-5637 CVE-2023-44981 Upstream summary: [email protected] reports: Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL […]

Read more
FreeBSD 12 — gstreamer1-plugins-jpeg — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — gstreamer1-plugins-jpeg — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 June 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gstreamer1-plugins-jpeg — NULL-pointer dereferences in JPEG decoder Related CVEs: CVE-2024-47599 Upstream summary: The GStreamer Security Center reports: Insufficient error handling in the JPEG decoder that can lead to NULL-pointer dereferences, […]

Read more
FreeBSD 12 — clamav-lts — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — clamav-lts — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 June 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: clamav — Possbile denial-of-service vulnerability Related CVEs: CVE-2022-20698 CVE-2022-20770 CVE-2022-20771 CVE-2022-20785 CVE-2022-20792 CVE-2022-20796 CVE-2022-20803 CVE-2023-20032  +8 more Upstream summary: The ClamAV project reports: A possible buffer overflow read bug is […]

Read more
FreeBSD 12 — py39-wagtail — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py39-wagtail — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 June 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-wagtail — stored XSS vulnerability Related CVEs: CVE-2023-28836 CVE-2023-28837 Upstream summary: A stored cross-site scripting (XSS) vulnerability exists on ModelAdmin views within the Wagtail admin interface. A user with a […]

Read more
FreeBSD 12 — emacs — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — emacs — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 June 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Emacs — Arbitrary code execution vulnerability Related CVEs: CVE-2005-0100 CVE-2008-3949 CVE-2012-3479 CVE-2022-45939 CVE-2022-48337 CVE-2022-48338 CVE-2022-48339 CVE-2024-30202  +5 more Upstream summary: Problem Description A shell injection vulnerability exists in GNU Emacs […]

Read more
FreeBSD 12 — keycloak — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — keycloak — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 June 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: keycloak — Multiple security fixes Related CVEs: CVE-2021-10039 CVE-2021-10270 CVE-2021-10451 CVE-2021-10492 CVE-2021-44549 CVE-2021-9666 CVE-2022-40151 CVE-2022-41966  +2 more Upstream summary: Keycloak reports: This update includes 2 security fixes: CVE-2024-11734: Unrestricted admin […]

Read more
FreeBSD 12 — py37-borgbackup — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py37-borgbackup — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 June 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Borg (Backup) — flaw in cryptographic authentication scheme in Borg allowed an attacker to fake archives and indirectly cause backup data loss. Related CVEs: CVE-2023-36811 Upstream summary: Thomas Waldmann reports: […]

Read more
CHAT