FreeBSD 13

FreeBSD 13 — rubygem-websocket-extensions — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem-websocket-extensions — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: websocket-extensions — ReDoS vulnerability Related CVEs: CVE-2020-7663 Upstream summary: Changelog: Remove a ReDoS vulnerability in the header parser (CVE-2020-7663) Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 13 — ktorrent — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ktorrent — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ktorrent — multiple vulnerabilities Related CVEs: CVE-2007-1384 CVE-2007-1385 Upstream summary: Two problems have been found in KTorrent: KTorrent does not properly sanitize file names to filter out ".." components, so […]

Read more
FreeBSD 13 — php70-imap — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — php70-imap — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php-imap — imap_open allows to run arbitrary shell commands via mailbox parameter Upstream summary: The PHP team reports: imap_open allows to run arbitrary shell commands via mailbox parameter. Table of […]

Read more
FreeBSD 13 — dia — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — dia — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dia — remote command execution vulnerability Related CVEs: CVE-2006-1550 CVE-2008-5984 Upstream summary: Security Focus reports: An attacker could exploit this issue by enticing an unsuspecting victim to execute the vulnerable […]

Read more
FreeBSD 13 — newsfetch — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — newsfetch — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: newsfetch — server response buffer overflow vulnerability Related CVEs: CVE-2005-0132 Upstream summary: The newsfetch program uses the sscanf function to read information from server responses into static memory buffers. Unfortunately […]

Read more
FreeBSD 13 — jabber — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — jabber — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fd_set — bitmap index overflow in multiple applications Related CVEs: CVE-2004-1378 Upstream summary: 3APA3A reports: If programmer fails to check socket number before using select() or fd_set macros, it's possible […]

Read more
FreeBSD 13 — rubygem-activeresource — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem-activeresource — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rails — multiple vulnerabilities Related CVEs: CVE-2013-4491 CVE-2013-6414 CVE-2013-6415 CVE-2013-6416 CVE-2013-6417 Upstream summary: Rails weblog: Rails 3.2.16 and 4.0.2 have been released! These two releases contain important security fixes, so […]

Read more
FreeBSD 13 — rubygem-rest-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem-rest-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rest-client — plaintext password disclosure Related CVEs: CVE-2015-1820 CVE-2015-3448 Upstream summary: The open sourced vulnerability database reports: REST Client for Ruby contains a flaw that is due to the application […]

Read more
FreeBSD 13 — monitorix — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — monitorix — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: monitorix — serious bug in the built-in HTTP server Upstream summary: Monitorix Project reports: A serious bug in the built-in HTTP server. It was discovered that the handle_request() routine did […]

Read more
FreeBSD 13 — wine — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — wine — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 March 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wine — information disclosure due to insecure temporary file handling Related CVEs: CVE-2005-0787 Upstream summary: Due to insecure temporary file creation in the Wine Windows emulator, it is possible for […]

Read more
CHAT