FreeBSD 13

FreeBSD 13 — py37-pyrad — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py37-pyrad — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pyrad — multiple vulnerabilities Related CVEs: CVE-2013-0294 CVE-2013-0342 Upstream summary: Nathaniel McCallum reports: packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which […]

Read more
FreeBSD 13 — foreman-proxy — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — foreman-proxy — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: foreman-proxy SSL verification issue Related CVEs: CVE-2014-3691 Upstream summary: Foreman Security reports: The smart proxy when running in an SSL-secured mode permits incoming API calls to any endpoint without requiring, […]

Read more
FreeBSD 13 — evolution-data-server — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — evolution-data-server — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: evolution-data-server — remote execution of arbitrary code vulnerability Related CVEs: CVE-2007-3257 Upstream summary: Debian project reports: It was discovered that the IMAP code in the Evolution Data Server performs insufficient […]

Read more
FreeBSD 13 — bmon — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — bmon — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bmon — unsafe set-user-ID application Upstream summary: Jon Nistor reported that the FreeBSD port of bmon was installed set-user-ID root, and executes commands using relative paths. This could allow local […]

Read more
FreeBSD 13 — iodine — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — iodine — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: iodined — authentication bypass Upstream summary: Erik Ekman of the iodine project reports: The client could bypass the password check by continuing after getting error from the server and guessing […]

Read more
FreeBSD 13 — wzdftpd — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — wzdftpd — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wzdftpd — remote DoS Upstream summary: wzdftpd contains a potential remote Denial-of-Service. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – […]

Read more
FreeBSD 13 — tnftp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — tnftp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tnftp — mget does not check for directory escapes Related CVEs: CVE-2004-1294 Upstream summary: When downloading a batch of files from an FTP server the mget command does not check […]

Read more
FreeBSD 13 — ilohamail — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ilohamail — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: "Content-Type" XSS vulnerability affecting other webmail systems Related CVEs: CVE-2004-0519 Upstream summary: Roman Medina-Heigl Hernandez did a survey which other webmail systems where vulnerable to a bug he discovered in […]

Read more
FreeBSD 13 — bogofilter-tdb — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — bogofilter-tdb — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bogofilter — RFC 2047 decoder denial-of-service vulnerability Related CVEs: CVE-2004-1007 Upstream summary: The bogofilter team has been provided with a test case of a malformatted (non-conformant) RFC-2047 encoded word that […]

Read more
FreeBSD 13 — libXrender — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libXrender — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: X.org libraries — multiple vulnerabilities Related CVEs: CVE-2013-1981 CVE-2013-1982 CVE-2013-1983 CVE-2013-1984 CVE-2013-1985 CVE-2013-1986 CVE-2013-1987 CVE-2013-1988  +12 more Upstream summary: Matthieu Herrb reports: Tobias Stoeckmann from the OpenBSD project has discovered […]

Read more
CHAT