FreeBSD 13

FreeBSD 13 — node-devel — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — node-devel — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: node, iojs, and v8 — denial of service Related CVEs: CVE-2015-5380 Upstream summary: node reports: This release of Node.js fixes a bug that triggers an out-of-band write in V8's utf-8 […]

Read more
FreeBSD 13 — electrum — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — electrum — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: electrum — JSONRPC vulnerability Related CVEs: CVE-2018-6353 Upstream summary: MITRE reports: JSONRPC vulnerability Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution […]

Read more
FreeBSD 13 — linux_base — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux_base — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: linux_base — vulnerabilities in Red Hat 7.1 libraries Related CVEs: CVE-2002-0029 CVE-2004-0083 CVE-2004-0084 CVE-2004-0106 CVE-2004-0687 CVE-2004-0688 CVE-2004-0692 CVE-2004-0914 Upstream summary: Trevor Johnson reported that the Red Hat Linux RPMs used […]

Read more
FreeBSD 13 — rubygem19-activemodel — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem19-activemodel — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Ruby Activemodel Gem — Circumvention of attr_protected Related CVEs: CVE-2013-0276 Upstream summary: Aaron Patterson reports: The attr_protected method allows developers to specify a blacklist of model attributes which users should […]

Read more
FreeBSD 13 — nvidia-driver — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — nvidia-driver — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: NVIDIA UNIX driver — multiple vulnerabilities in the kernel mode layer handler Related CVEs: CVE-2006-5379 CVE-2012-0946 CVE-2012-4225 CVE-2013-0131 CVE-2014-8093 CVE-2014-8098 CVE-2014-8298 CVE-2017-0309  +7 more Upstream summary: NVIDIA Unix security team […]

Read more
FreeBSD 13 — zh-cce — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — zh-cce — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: CCE contains exploitable buffer overflows Upstream summary: The Chinese Console Environment contains exploitable buffer overflows. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
FreeBSD 13 — mysql-connector-odbc — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mysql-connector-odbc — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 28 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL — Multiple vulnerabilities Related CVEs: CVE-2021-22946 CVE-2021-3712 CVE-2022-1941 CVE-2022-2097 CVE-2022-21245 CVE-2022-21249 CVE-2022-21253 CVE-2022-21254  +12 more Upstream summary: Oracle reports: This Critical Patch Update contains 37 new security patches, plus […]

Read more
FreeBSD 13 — py35-urllib — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py35-urllib — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: urllib3 — multiple vulnerabilities Related CVEs: CVE-2018-20060 CVE-2019-11236 CVE-2019-11324 Upstream summary: NIST reports: (by search in the range 2018/01/01 – 2019/11/10): urllib3 before version 1.23 does not remove the Authorization […]

Read more
FreeBSD 13 — mariadb106-client — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mariadb106-client — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MariaDB — Multiple vulnerabilities Related CVEs: CVE-2021-46669 CVE-2022-27376 CVE-2022-27377 CVE-2022-27378 CVE-2022-27379 CVE-2022-27380 CVE-2022-27381 CVE-2022-27382  +12 more Upstream summary: The MariaDB project reports: See linked CVE's for details. Table of contents […]

Read more
FreeBSD 13 — py27-yaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py27-yaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-yaml — FullLoader (still) exploitable for arbitrary command execution Related CVEs: CVE-2017-18342 CVE-2020-1747 Upstream summary: Riccardo Schirone (https://github.com/ret2libc) reports: In FullLoader python/object/new constructor, implemented by construct_python_object_apply, has support for setting […]

Read more
CHAT