FreeBSD 13

FreeBSD 13 — puppetserver — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — puppetserver — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: puppet — Unsafe HTTP Redirect Related CVEs: CVE-2018-1000180 CVE-2018-1000613 CVE-2020-7943 CVE-2021-27023 Upstream summary: Puppet reports: A flaw was discovered in Puppet Agent and Puppet Server that may result in a […]

Read more
FreeBSD 13 — py37-fail2ban — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py37-fail2ban — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fail2ban — possible RCE vulnerability in mailing action using mailutils Related CVEs: CVE-2021-32749 Upstream summary: Jakub Żoczek reports: Command mail from mailutils package used in mail actions like mail-whois can […]

Read more
How to Build Docker Images with Multi-Stage Builds on FreeBSD 13 — step-by-step FreeBSD 13 tutorial on Progressive Robot

How to Build Docker Images with Multi-Stage Builds on FreeBSD 13

Introduction Deploying build docker images with multi-stage builds on freebsd 13 on a FreeBSD 13 machine differs from Linux in several important ways: packages come from the FreeBSD Ports Collection or the binary pkg repository, services are registered in /etc/rc.conf via sysrc(8), and firewall rules are written in pf.conf(5) syntax. This tutorial stays entirely within […]

Read more
FreeBSD 13 — a2ps — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — a2ps — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: a2ps — format string vulnerability Related CVEs: CVE-2015-8107 Upstream summary: Jong-Gwon Kim reports: When user runs a2ps with malicious crafted pro(a2ps prologue) file, an attacker can execute arbitrary code. Table […]

Read more
FreeBSD 13 — mod_dav — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mod_dav — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mod_dav — lock related denial-of-service Related CVEs: CVE-2004-0809 Upstream summary: A malicious user with DAV write privileges can trigger a null pointer dereference in the Apache mod_dav module. This could […]

Read more
FreeBSD 13 — qemu-sbruno — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — qemu-sbruno — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: qemu — denial of service vulnerability Related CVEs: CVE-2015-1779 CVE-2015-3209 CVE-2015-3214 CVE-2015-3456 CVE-2015-5154 CVE-2015-5158 CVE-2015-5165 CVE-2015-5166  +12 more Upstream summary: Daniel P. Berrange reports: The VNC server websockets decoder will […]

Read more
FreeBSD 13 — viewcvs — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — viewcvs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: viewcvs — information leakage Related CVEs: CVE-2004-0915 Upstream summary: The hide_cvsroot and forbidden configuration options are not properly honored by viewcvs when exporting to a tar file which can lead […]

Read more
FreeBSD 13 — koffice-kde — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — koffice-kde — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Calligra, KOffice — input validation failure Related CVEs: CVE-2012-3455 CVE-2012-3456 Upstream summary: KDE Security Advisory reports: A flaw has been found which can allow malicious code to take advantage of […]

Read more
FreeBSD 13 — py35-yaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py35-yaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-yaml — FullLoader (still) exploitable for arbitrary command execution Related CVEs: CVE-2017-18342 CVE-2020-1747 Upstream summary: Riccardo Schirone (https://github.com/ret2libc) reports: In FullLoader python/object/new constructor, implemented by construct_python_object_apply, has support for setting […]

Read more
CHAT