FreeBSD 14

FreeBSD 14 — xerces-c — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — xerces-c — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: shibboleth-sp — vulnerable to forged user attribute data Related CVEs: CVE-2016-0729 CVE-2016-2099 CVE-2016-4463 CVE-2018-0486 CVE-2018-0489 Upstream summary: Shibboleth consortium reports: Shibboleth SP software vulnerable to additional data forgery flaws The […]

Read more
FreeBSD 14 — courier-imap — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — courier-imap — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: courier-imap — format string vulnerability in debug mode Related CVEs: CVE-2004-0224 CVE-2004-0777 Upstream summary: An iDEFENSE security advisory describes a format string vulnerability that could be exploited when Courier-IMAP is […]

Read more
FreeBSD 14 — dovecot — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — dovecot — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Dovecot — DoS Related CVEs: CVE-2008-4577 CVE-2008-4578 CVE-2009-3897 CVE-2011-1929 CVE-2017-15132 CVE-2017-2669 CVE-2019-10691 CVE-2019-11494  +12 more Upstream summary: Dovecot reports: A DoS is possible with a large number of address headers […]

Read more
FreeBSD 14 — rubygem-activerecord — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rubygem-activerecord — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Rails — multiple vulnerabilities Related CVEs: CVE-2013-0155 CVE-2013-0156 CVE-2013-1854 CVE-2013-1856 CVE-2013-1857 CVE-2013-4491 CVE-2013-6414 CVE-2013-6415  +11 more Upstream summary: Ruby on Rails blog: Rails version 5.2.4.5, 6.0.3.5 and 6.1.2.1 have been […]

Read more
FreeBSD 14 — mariadb100-client — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mariadb100-client — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mysql — denial of service vulnerability Related CVEs: CVE-2015-3152 CVE-2015-4792 CVE-2015-4802 CVE-2015-4807 CVE-2015-4815 CVE-2015-4826 CVE-2015-4830 CVE-2015-4836  +12 more Upstream summary: Openwall reports: C client library for MySQL (libmysqlclient.so) has use-after-free […]

Read more
FreeBSD 14 — proftpd — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — proftpd — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: proftpd — user chroot escape vulnerability Related CVEs: CVE-2003-0831 CVE-2004-0432 CVE-2005-2390 CVE-2006-5815 CVE-2006-6170 CVE-2008-4242 CVE-2008-4247 CVE-2009-0542  +5 more Upstream summary: NVD reports: ProFTPD … controls whether the home directory of […]

Read more
FreeBSD 14 — tarsnap — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — tarsnap — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tarsnap — buffer overflow and local DoS Upstream summary: Colin Percival reports: 1. SECURITY FIX: When constructing paths of objects being archived, a buffer could overflow by one byte upon […]

Read more
FreeBSD 14 — ja-bugzilla — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ja-bugzilla — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bugzilla — multiple vulnerabilities Related CVEs: CVE-2004-1061 CVE-2005-2173 CVE-2005-2174 CVE-2006-0913 CVE-2006-0914 CVE-2006-0915 CVE-2006-0916 CVE-2006-2420  +9 more Upstream summary: A Bugzilla Security Advisory reports: Cross-Site Scripting When viewing a single bug […]

Read more
FreeBSD 14 — ktorrent — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ktorrent — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ktorrent — multiple vulnerabilities Related CVEs: CVE-2007-1384 CVE-2007-1385 Upstream summary: Two problems have been found in KTorrent: KTorrent does not properly sanitize file names to filter out ".." components, so […]

Read more
FreeBSD 14 — php70-wddx — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php70-wddx — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 July 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2015-8874 CVE-2016-5766 CVE-2016-5767 CVE-2016-5768 CVE-2016-5769 CVE-2016-5770 CVE-2016-5771 CVE-2016-5772  +1 more Upstream summary: The PHP Group reports: Please reference CVE/URL list for details Table of […]

Read more
CHAT