FreeBSD 13

FreeBSD 13 — snappymail-php — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — snappymail-php — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 December 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: SnappyMail — multiple mXSS in HTML sanitizer Related CVEs: CVE-2024-45800 Upstream summary: Oskar reports: SnappyMail uses the `cleanHtml()` function to cleanup HTML and CSS in emails. Research discovered that the […]

Read more
FreeBSD 13 — gitlab-ee — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — gitlab-ee — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 December 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Gitlab — vulnerabilities Related CVEs: CVE-2023-6195 CVE-2023-6502 CVE-2023-6682 CVE-2023-6688 CVE-2023-7045 CVE-2024-0231 CVE-2024-10043 CVE-2024-10219  +12 more Upstream summary: Gitlab reports: Cross-site Scripting issue in Analytics dashboard chart rendering impacts GitLab EE […]

Read more
FreeBSD 13 — postgresql12-server — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — postgresql12-server — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 December 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgreSQL — SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID Related CVEs: CVE-2020-1720 CVE-2021-23214 CVE-2021-23222 CVE-2021-3677 CVE-2022-1552 CVE-2024-10976 CVE-2024-10978 CVE-2024-7348 Upstream summary: PostgreSQL project reports: Incorrect privilege assignment […]

Read more
FreeBSD 13 — gogs — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — gogs — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 December 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gogs — Multiple vulnerabilities Related CVEs: CVE-2022-1464 CVE-2024-39930 CVE-2024-39931 CVE-2024-39932 CVE-2024-39933 CVE-2024-44625 Upstream summary: [email protected] reports: CVE-2024-44625: Directory Traversal via the editFilePost function of internal/route/repo/editor.go. CVE-2024-39933: Gogs allows argument injection […]

Read more
FreeBSD 13 — emacs-nox — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — emacs-nox — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 December 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Emacs — Arbitrary code execution vulnerability Related CVEs: CVE-2022-45939 CVE-2022-48337 CVE-2022-48338 CVE-2022-48339 CVE-2024-30202 CVE-2024-30203 CVE-2024-30204 CVE-2024-30205  +2 more Upstream summary: Problem Description A shell injection vulnerability exists in GNU Emacs […]

Read more
FreeBSD 13 — qt6-networkauth — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — qt6-networkauth — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 December 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: QtNetworkAuth — predictable seeding of PRNG in QAbstractOAuth Related CVEs: CVE-2024-36048 Upstream summary: Andy Shaw reports: The OAuth1 implementation in QtNetworkAuth created nonces using a PRNG that was seeded with […]

Read more
FreeBSD 13 — plasma6-plasma-workspace — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — plasma6-plasma-workspace — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 December 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: plasma[56]-plasma-workspace — Unauthorized users can access session manager Related CVEs: CVE-2024-36041 Upstream summary: David Edmundson reports: KSmserver, KDE's XSMP manager, incorrectly allows connections via ICE based purely on the host, […]

Read more
FreeBSD 13 — arti — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — arti — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 December 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Arti — Security issues related to circuit construction Related CVEs: CVE-2024-35312 CVE-2024-35313 Upstream summary: Tor Project reports: When building anonymizing circuits to or from an onion service with 'lite' vanguards […]

Read more
FreeBSD 13 — libgit — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libgit — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 29 November 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Libgit2 — multiple vulnerabilities Related CVEs: CVE-2018-10887 CVE-2018-10888 CVE-2018-11235 CVE-2018-17456 CVE-2024-24577 Upstream summary: Git community reports: A bug in git_revparse_single is fixed that could have caused the function to enter […]

Read more
FreeBSD 13 — eza — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — eza — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 November 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Libgit2 — multiple vulnerabilities Related CVEs: CVE-2024-24577 Upstream summary: Git community reports: A bug in git_revparse_single is fixed that could have caused the function to enter an infinite loop given […]

Read more
CHAT