FreeBSD 13

FreeBSD 13 — junkbuster — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — junkbuster — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: junkbuster — heap corruption vulnerability and configuration modification vulnerability Related CVEs: CVE-2005-1108 CVE-2005-1109 Upstream summary: A Debian advisory reports: James Ranson discovered that an attacker can modify the referrer setting […]

Read more
FreeBSD 13 — rubygem-mail — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem-mail — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-mail — multiple vulnerabilities Related CVEs: CVE-2011-0739 CVE-2012-2139 CVE-2012-2140 Upstream summary: rubygem-mail — multiple vulnerabilities Two issues were fixed. They are a file system traversal in file_delivery method and arbitrary […]

Read more
FreeBSD 13 — ethereal-lite — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ethereal-lite — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wireshark — PCNFSD Dissector Denial of Service Vulnerability Related CVEs: CVE-2004-0504 CVE-2004-0505 CVE-2004-0506 CVE-2004-0507 CVE-2004-0633 CVE-2004-0634 CVE-2004-0635 CVE-2004-1139  +12 more Upstream summary: Secunia reports: A vulnerability has been reported in […]

Read more
FreeBSD 13 — json-c — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — json-c — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: json-c — integer overflow and out-of-bounds write via a large JSON file Related CVEs: CVE-2020-12762 Upstream summary: Tobias Stöckmann reports: I have discovered a way to trigger an out of […]

Read more
FreeBSD 13 — libebml — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libebml — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libebml — multiple vulnerabilities Related CVEs: CVE-2015-8789 CVE-2015-8790 CVE-2015-8791 Upstream summary: Mortiz Bunkus reports: Multiple invalid memory accesses vulnerabilities. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 13 — linux-png — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-png — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libpng stack-based buffer overflow and other code concerns Related CVEs: CVE-2004-0421 CVE-2004-0597 CVE-2004-0598 CVE-2004-0599 Upstream summary: Chris Evans has discovered multiple vulnerabilities in libpng, which can be exploited by malicious […]

Read more
FreeBSD 13 — exact-image — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — exact-image — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dcraw — integer overflow condition Related CVEs: CVE-2015-3885 Upstream summary: ocert reports: The dcraw tool, as well as several other projects re-using its code, suffers from an integer overflow condition […]

Read more
FreeBSD 13 — phpmyfaq — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — phpmyfaq — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: phpmyfaq — multiple vulnerabilities Related CVEs: CVE-2005-2498 CVE-2005-3046 CVE-2005-3047 CVE-2005-3048 CVE-2005-3049 CVE-2005-3050 CVE-2014-0813 CVE-2014-0814  +2 more Upstream summary: phpmyfaq developers report: Multiple XSS vulnerabilities Table of contents Symptom & Impact […]

Read more
FreeBSD 13 — perdition — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — perdition — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: perdition — str_vwrite format string vulnerability Related CVEs: CVE-2007-5740 Upstream summary: SEC-Consult reports: Perdition IMAP is affected by a format string bug in one of its IMAP output-string formatting functions. […]

Read more
CHAT