FreeBSD 12

FreeBSD 12 — serendipity — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — serendipity — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 June 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: serendipity — XSS Related CVEs: CVE-2008-1385 CVE-2008-1386 CVE-2019-11870 Upstream summary: MITRE: Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the […]

Read more
How to Secure Apache with Let's Encrypt on FreeBSD 12 — step-by-step FreeBSD 12 tutorial on Progressive Robot

How to Secure Apache with Let’s Encrypt on FreeBSD 12

Introduction Deploying secure apache with let’s encrypt on freebsd 12 on a FreeBSD 12 machine differs from Linux in several important ways: packages come from the FreeBSD Ports Collection or the binary pkg repository, services are registered in /etc/rc.conf via sysrc(8), and firewall rules are written in pf.conf(5) syntax. This tutorial stays entirely within the […]

Read more
FreeBSD 12 — py37-ecdsa — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py37-ecdsa — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 June 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: security/py-ecdsa — multiple issues Related CVEs: CVE-2019-14853 CVE-2019-14859 Upstream summary: py-ecdsa developers report: Fix CVE-2019-14853 – possible DoS caused by malformed signature decoding. Fix CVE-2019-14859 – signature malleability caused by […]

Read more
FreeBSD 12 — pspp — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — pspp — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 June 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pspp — multiple vulnerabilities Related CVEs: CVE-2017-10791 CVE-2017-10792 CVE-2017-12958 CVE-2017-12959 CVE-2017-12960 CVE-2017-12961 Upstream summary: CVE Details reports: There is an Integer overflow in the hash_int function of the libpspp library […]

Read more
FreeBSD 12 — linux-f10-expat — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-f10-expat — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 June 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: expat2 — Parser crash with specially formatted UTF-8 sequences Related CVEs: CVE-2009-3720 Upstream summary: CVE reports: The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, […]

Read more
FreeBSD 12 — postgresql95-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — postgresql95-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 June 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgresSQL — TYPE in pg_temp execute arbitrary SQL during `SECURITY DEFINER` execution Related CVEs: CVE-2016-0766 CVE-2016-0773 CVE-2016-2193 CVE-2016-3065 CVE-2016-5423 CVE-2016-5424 CVE-2017-15098 CVE-2017-15099  +12 more Upstream summary: The PostgreSQL project reports: […]

Read more
FreeBSD 12 — fspd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — fspd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 June 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fsp buffer overflow and directory traversal vulnerabilities Related CVEs: CVE-2003-1022 CVE-2004-0011 Upstream summary: The Debian security team reported a pair of vulnerabilities in fsp: A vulnerability was discovered in fsp, […]

Read more
FreeBSD 12 — monkey — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — monkey — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 June 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: monkey — improper input validation vulnerability Upstream summary: Census Labs reports: We have discovered a remotely exploitable "improper input validation" vulnerability in the Monkey web server that allows an attacker […]

Read more
FreeBSD 12 — sddm — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — sddm — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 June 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: X11 Session — SDDM allows unauthorised unlocking Related CVEs: CVE-2018-14345 Upstream summary: MITRE reports: An issue was discovered in SDDM through 0.17.0. If configured with ReuseSession=true, the password is not […]

Read more
CHAT