FreeBSD 12

FreeBSD 12 — samba — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — samba — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 January 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: samba — multiple vulnerabilities Related CVEs: CVE-2004-0082 CVE-2004-0600 CVE-2004-0686 CVE-2004-0807 CVE-2004-0808 CVE-2004-0815 CVE-2004-0882 CVE-2004-0930  +12 more Upstream summary: The Samba Team reports: CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion […]

Read more
FreeBSD 12 — py38-social-auth-app-django — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py38-social-auth-app-django — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 January 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-social-auth-app-django — Improper Handling of Case Sensitivity Related CVEs: CVE-2024-32879 Upstream summary: GitHub Advisory Database: Python Social Auth is a social authentication/registration mechanism. Prior to version 5.4.1, due to default […]

Read more
FreeBSD 12 — gstreamer1-plugins-ogg — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — gstreamer1-plugins-ogg — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 January 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gstreamer1-plugins-ogg — Out-of-bounds write in Ogg demuxer Related CVEs: CVE-2024-47615 Upstream summary: The GStreamer Security Center reports: An out-of-bounds write in the Ogg demuxer that can cause crashes for certain […]

Read more
FreeBSD 12 — bind — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — bind — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 January 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: DNSSEC validators — denial-of-service/CPU exhaustion from KeyTrap and NSEC3 vulnerabilities Related CVEs: CVE-2003-0914 CVE-2005-0033 CVE-2005-0034 CVE-2006-4095 CVE-2006-4096 CVE-2009-0696 CVE-2011-1910 CVE-2011-2464  +12 more Upstream summary: Simon Kelley reports: If DNSSEC validation […]

Read more
FreeBSD 12 — postgresql12-server — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — postgresql12-server — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 January 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgreSQL — SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID Related CVEs: CVE-2020-1720 CVE-2021-23214 CVE-2021-23222 CVE-2021-3677 CVE-2022-1552 CVE-2024-10976 CVE-2024-10978 CVE-2024-7348 Upstream summary: PostgreSQL project reports: Incorrect privilege assignment […]

Read more
FreeBSD 12 — libspf — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libspf — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 January 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libspf2 — Integer Underflow Remote Code Execution Related CVEs: CVE-2008-2469 CVE-2023-42118 Upstream summary: Trendmicro ZDI reports: Integer Underflow Remote Code Execution Vulnerability The specific flaw exists within the parsing of […]

Read more
FreeBSD 12 — openssl31-quictls — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — openssl31-quictls — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 January 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenSSL — OOB memory access vulnerability Related CVEs: CVE-2023-5678 CVE-2023-6129 CVE-2023-6237 CVE-2024-0727 CVE-2024-2511 CVE-2024-4603 CVE-2024-4741 CVE-2024-5535  +2 more Upstream summary: The OpenSSL project reports: Low-level invalid GF(2^m) parameters lead to […]

Read more
FreeBSD 12 — frr — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — frr — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 January 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: frr – BGP Related CVEs: CVE-2017-15865 CVE-2024-31950 CVE-2024-31951 CVE-2024-44070 Upstream summary: [email protected] reports: An issue was discovered in FRRouting (FRR). bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream […]

Read more
FreeBSD 12 — emacs-nox — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — emacs-nox — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 January 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Emacs — Arbitrary code execution vulnerability Related CVEs: CVE-2022-45939 CVE-2022-48337 CVE-2022-48338 CVE-2022-48339 CVE-2024-30202 CVE-2024-30203 CVE-2024-30204 CVE-2024-30205  +2 more Upstream summary: Problem Description A shell injection vulnerability exists in GNU Emacs […]

Read more
CHAT