FreeBSD 13

FreeBSD 13 — p5-UI-Dialog — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — p5-UI-Dialog — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-UI-Dialog — shell command execution vulnerability Related CVEs: CVE-2008-7315 Upstream summary: Matthijs Kooijman reports: It seems that the whiptail, cdialog and kdialog backends apply some improper escaping in their shell […]

Read more
FreeBSD 13 — nbsmtp — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — nbsmtp — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: nbsmtp — format string vulnerability Upstream summary: When nbsmtp is executed in debug mode, server messages will be printed to stdout and logged via syslog. Syslog is used insecurely and […]

Read more
FreeBSD 13 — punbb — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — punbb — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: punbb — NULL byte injection vulnerability Related CVEs: CVE-2006-4759 Upstream summary: CVE Mitre reports: PunBB 1.2.12 does not properly handle an avatar directory pathname ending in %00, which allows remote […]

Read more
FreeBSD 13 — msmtp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — msmtp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: msmtp — certificate-verification issue Related CVEs: CVE-2019-8337 Upstream summary: msmtp developers report: In msmtp 1.8.2, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. Table of contents […]

Read more
FreeBSD 13 — electrum-py — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — electrum-py — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: electrum — JSONRPC vulnerability Related CVEs: CVE-2018-6353 Upstream summary: MITRE reports: JSONRPC vulnerability Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution […]

Read more
FreeBSD 13 — mod_dav_svn — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mod_dav_svn — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Subversion — Multiple vulnerabilities in server code Related CVEs: CVE-2014-3580 CVE-2014-8108 CVE-2015-0202 CVE-2015-0248 CVE-2015-0251 CVE-2015-5259 CVE-2015-5343 CVE-2021-28544  +1 more Upstream summary: Subversion project reports: Subversion servers reveal 'copyfrom' paths that […]

Read more
FreeBSD 13 — libXv — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libXv — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 9 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: X.org libraries — multiple vulnerabilities Related CVEs: CVE-2013-1981 CVE-2013-1982 CVE-2013-1983 CVE-2013-1984 CVE-2013-1985 CVE-2013-1986 CVE-2013-1987 CVE-2013-1988  +12 more Upstream summary: Matthieu Herrb reports: Tobias Stoeckmann from the OpenBSD project has discovered […]

Read more
FreeBSD 13 — ghostscript9-agpl — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ghostscript9-agpl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ghostscript — denial of service (crash) via crafted Postscript files Related CVEs: CVE-2015-3228 Upstream summary: MITRE reports: Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier […]

Read more
CHAT