FreeBSD 12

FreeBSD 12 — mozjpeg — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mozjpeg — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 December 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mozjpeg — heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file Related CVEs: CVE-2020-13790 Upstream summary: NIST reports: Heap-based buffer over-read in get_rgb_row() in rdppm.c via […]

Read more
FreeBSD 12 — sqlite — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — sqlite — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 December 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: SQLite < 3.50.3 — CWE-190 Integer Overflow or Wraparound in FTS5 module Related CVEs: CVE-2015-3414 CVE-2015-3415 CVE-2015-3416 CVE-2016-6153 CVE-2017-10989 CVE-2018-8740 CVE-2019-5018 CVE-2020-11655  +12 more Upstream summary: https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g reports: An integer […]

Read more
FreeBSD 12 — py38-bleach — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py38-bleach — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 December 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-bleach — regular expression denial-of-service Related CVEs: CVE-2020-6817 Upstream summary: Bleach developers reports: bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to […]

Read more
FreeBSD 12 — typo3-9-php — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — typo3-9-php — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 29 November 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: typo3 — multiple vulnerabilities Related CVEs: CVE-2019-10912 CVE-2019-12747 CVE-2019-12748 CVE-2020-11063 CVE-2020-11064 CVE-2020-11065 CVE-2020-11066 CVE-2020-11067  +3 more Upstream summary: Typo3 Team reports: In case an attacker manages to generate a valid […]

Read more
FreeBSD 12 — rubygem-websocket-extensions — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rubygem-websocket-extensions — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 November 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: websocket-extensions — ReDoS vulnerability Related CVEs: CVE-2020-7663 Upstream summary: Changelog: Remove a ReDoS vulnerability in the header parser (CVE-2020-7663) Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 12 — rubygem-activesupport — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rubygem-activesupport — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 November 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Rails — multiple vulnerabilities Related CVEs: CVE-2007-3227 CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 CVE-2013-0155 CVE-2013-0156 CVE-2013-1854 CVE-2013-1856  +12 more Upstream summary: Ruby on Rails blog: Hi everyone! Rails 5.2.4.3 and 6.0.3.1 have been […]

Read more
FreeBSD 12 — libzmq — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libzmq — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 November 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libzmq4 — Denial of Service Related CVEs: CVE-2014-9721 CVE-2019-13132 CVE-2019-6250 CVE-2020-15166 Upstream summary: Google's oss-fuzz project reports: Denial-of-Service on CURVE/ZAP-protected servers by unauthenticated clients. If a raw TCP socket is […]

Read more
FreeBSD 12 — rubygem-kaminari-core — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rubygem-kaminari-core — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 November 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: kaminari — potential XSS vulnerability Related CVEs: CVE-2020-11082 Upstream summary: Kaminari Security Advisories: There was a vulnerability in versions of Kaminari that would allow an attacker to inject arbitrary code […]

Read more
FreeBSD 12 — libexif — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libexif — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 November 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libexif — multiple vulnerabilities Related CVEs: CVE-2005-0664 CVE-2012-2812 CVE-2012-2813 CVE-2012-2814 CVE-2012-2836 CVE-2012-2837 CVE-2012-2840 CVE-2012-2841  +2 more Upstream summary: Release notes: Lots of fixes exposed by fuzzers like AFL, ClusterFuzz, OSSFuzz […]

Read more
How to Set Up ModSecurity WAF with Apache on FreeBSD 12 — step-by-step FreeBSD 12 tutorial on Progressive Robot

How to Set Up ModSecurity WAF with Apache on FreeBSD 12

Introduction How to Set Up ModSecurity WAF with Apache on FreeBSD 12 is a core administration task for any FreeBSD 12 server operator. FreeBSD 12 ships with the 15.0-RELEASE kernel, ZFS as the default root filesystem, Capsicum capability sandboxing improvements, and an updated ports tree. Unlike Linux distributions, FreeBSD uses rc(8) for service management, pf […]

Read more
CHAT