FreeBSD 13

FreeBSD 13 — darktable — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — darktable — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 August 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dcraw — integer overflow condition Related CVEs: CVE-2015-3885 Upstream summary: ocert reports: The dcraw tool, as well as several other projects re-using its code, suffers from an integer overflow condition […]

Read more
FreeBSD 13 — py37-impacket — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py37-impacket — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 31 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-impacket — multiple path traversal vulnerabilities Related CVEs: CVE-2021-31800 Upstream summary: asolino reports: Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a […]

Read more
FreeBSD 13 — timidity++-motif — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — timidity++-motif — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 31 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: TiMidity++ — Multiple vulnerabilities Related CVEs: CVE-2017-11546 CVE-2017-11547 CVE-2017-11549 Upstream summary: qflb.wu of DBAPPSecurity reports: Ihe insert_note_steps function in readmidi.c in TiMidity++ 2.14.0 can cause a denial of service(divide-by-zero error […]

Read more
FreeBSD 13 — postgresql95-contrib — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — postgresql95-contrib — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgreSQL — minor security problems. Related CVEs: CVE-2016-2193 CVE-2016-3065 Upstream summary: PostgreSQL project reports: Security Fixes for RLS, BRIN This release closes security hole CVE-2016-2193 (https://access.redhat.com/security/cve/CVE-2016-2193), where a query plan […]

Read more
FreeBSD 13 — tptest — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — tptest — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tptest — pwd Remote Stack Buffer Overflow Upstream summary: SecurityFocus reports: TPTEST is prone to a remote stack-based buffer-overflow vulnerability. An attacker can exploit this issue to execute arbitrary code […]

Read more
FreeBSD 13 — py36-notebook — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py36-notebook — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Jupyter notebook — open redirect vulnerability Related CVEs: CVE-2018-8768 CVE-2019-10255 Upstream summary: Jupyter blog: Login pages tend to take a parameter for redirecting back to a page after successful login, […]

Read more
FreeBSD 13 — ghostscript-gpl — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ghostscript-gpl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ghostscript — zseticcspace() function buffer overflow vulnerability Related CVEs: CVE-2008-0411 Upstream summary: Chris Evans from the Google Security Team reports: Severity: parsing of evil PostScript file will result in arbitrary […]

Read more
FreeBSD 13 — mgetty+sendfax — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mgetty+sendfax — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mgetty+sendfax — symlink attack via insecure temporary files Related CVEs: CVE-2008-4936 Upstream summary: Debian reports: Faxspool in mgetty 1.1.36 allows local users to overwrite arbitrary files via a symlink attack […]

Read more
FreeBSD 13 — zh-zhcon — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — zh-zhcon — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zhcon — unauthorized file access Related CVEs: CVE-2005-0072 Upstream summary: Martin Joey Schulze reports: Erik Sjöund discovered that zhcon, a fast console CJK system using the Linux framebuffer, accesses a […]

Read more
CHAT