FreeBSD 13

FreeBSD 13 — dhcpcd — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — dhcpcd — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dhcpcd — remote code execution/denial of service Related CVEs: CVE-2014-7912 CVE-2014-7913 CVE-2016-1503 CVE-2016-1504 Upstream summary: MITRE reports: The get_option function in dhcp.c in dhcpcd before 6.2.0, as used in dhcpcd […]

Read more
FreeBSD 13 — py27-foolscap — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py27-foolscap — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-foolscap — local file inclusion Upstream summary: Brian Warner reports: The "flappserver" feature was found to have a vulnerability in the service-lookup code which, when combined with an attacker who […]

Read more
FreeBSD 13 — py24-pylons — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py24-pylons — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-pylons — Path traversal bug Upstream summary: Pylons team reports: The error.py controller uses paste.fileapp to serve the static resources to the browser. The default error.py controller uses os.path.join to […]

Read more
FreeBSD 13 — firebird-server — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — firebird-server — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: firebird — multiple remote buffer overflow vulnerabilities Upstream summary: RISE Security reports: There exists multiple vulnerabilities within functions of Firebird Relational Database, which when properly exploited can lead to remote […]

Read more
FreeBSD 13 — evolution — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — evolution — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: evolution — remote format string vulnerabilities Related CVEs: CVE-2005-0102 CVE-2005-2549 CVE-2005-2550 Upstream summary: A SITIC Vulnerability Advisory reports: Evolution suffers from several format string bugs when handling data from remote […]

Read more
FreeBSD 13 — ghostscript-afpl — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ghostscript-afpl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ghostscript — insecure temporary file creation vulnerability Related CVEs: CVE-2004-0967 Upstream summary: Ghostscript is affected by an insecure temporary file creation vulnerability. This issue is likely due to a design […]

Read more
FreeBSD 13 — freeimage — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — freeimage — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 30 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: freeimage — code execution vulnerability Related CVEs: CVE-2015-0852 CVE-2015-3885 CVE-2016-5684 Upstream summary: TALOS reports: An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. […]

Read more
FreeBSD 13 — proftpd-mysql — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — proftpd-mysql — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: proftpd — arbitrary code execution vulnerability with chroot Related CVEs: CVE-2005-2390 CVE-2006-5815 CVE-2006-6170 CVE-2008-4242 CVE-2008-4247 CVE-2009-0542 CVE-2009-0543 Upstream summary: The FreeBSD security advisory FreeBSD-SA-11:07.chroot reports: If ftpd is configured to […]

Read more
FreeBSD 13 — SSLtelnet — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — SSLtelnet — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Format string vulnerability in SSLtelnet Related CVEs: CVE-2004-0640 Upstream summary: SSLtelnet contains a format string vulnerability that could allow remote code execution and privilege escalation. Table of contents Symptom & […]

Read more
FreeBSD 13 — py311-suds — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py311-suds — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-suds — vulnerable to symlink attacks Related CVEs: CVE-2013-2217 Upstream summary: SUSE reports: cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries […]

Read more
CHAT