FreeBSD 14

FreeBSD 14 — node — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — node — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: NodeJS — Vulnerabilities Related CVEs: CVE-2011-4815 CVE-2011-4838 CVE-2011-5036 CVE-2011-5037 CVE-2015-0278 CVE-2015-5380 CVE-2016-0702 CVE-2016-0705  +12 more Upstream summary: Node.js reports: Code injection and privilege escalation through Linux capabilities- (High) http: Reading […]

Read more
FreeBSD 14 — zh-tin — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — zh-tin — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tin — buffer overflow vulnerabilities Upstream summary: Urs Janssen and Aleksey Salow report possible buffer overflows in tin versions 1.8.0 and 1.8.1. OpenPKG project elaborates there is an allocation off-by-one […]

Read more
FreeBSD 14 — mnemo — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mnemo — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mnemo — Cross site scripting vulnerabilities in several of the notepad name and note data fields Upstream summary: Announce of Mnemo H3 (2.0.3) (final): This [2.0.3] is a security release […]

Read more
FreeBSD 14 — mod_dav_svn-lts — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mod_dav_svn-lts — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Subversion — Multiple vulnerabilities in server code Related CVEs: CVE-2021-28544 CVE-2022-24070 Upstream summary: Subversion project reports: Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization […]

Read more
FreeBSD 14 — libntlm — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — libntlm — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libntlm — buffer overflow vulnerability Related CVEs: CVE-2019-17455 Upstream summary: NVD reports: Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, […]

Read more
FreeBSD 14 — diablo-jdk-freebsd — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — diablo-jdk-freebsd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: jdk — jar directory traversal vulnerability Related CVEs: CVE-2005-1080 Upstream summary: Pluf has discovered a vulnerability in Sun Java JDK/SDK, which potentially can be exploited by malicious people to compromise […]

Read more
FreeBSD 14 — bind9-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — bind9-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: DNSSEC validators — denial-of-service/CPU exhaustion from KeyTrap and NSEC3 vulnerabilities Related CVEs: CVE-2015-3193 CVE-2015-8000 CVE-2015-8461 CVE-2016-1285 CVE-2016-1286 CVE-2016-2088 CVE-2016-2775 CVE-2016-2776  +12 more Upstream summary: Simon Kelley reports: If DNSSEC validation […]

Read more
FreeBSD 14 — konversation — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — konversation — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: konversation — crash in IRC message parsing Related CVEs: CVE-2005-0129 CVE-2005-0130 CVE-2005-0131 CVE-2014-8483 CVE-2017-15923 Upstream summary: KDE reports: Konversation has support for colors in IRC messages. Any malicious user connected […]

Read more
FreeBSD 14 — linux-realplayer — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — linux-realplayer — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: linux-realplayer — multiple vulnerabilities Related CVEs: CVE-2005-0611 CVE-2005-1277 CVE-2005-2922 CVE-2006-0323 CVE-2007-2263 CVE-2007-2264 CVE-2007-3410 CVE-2007-5081 Upstream summary: Secunia reports: Multiple vulnerabilities have been reported in RealPlayer/RealOne/HelixPlayer, which can be exploited by […]

Read more
FreeBSD 14 — openzfs-kmod — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — openzfs-kmod — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sysutils/openzfs-kmod — critical permissions issues Upstream summary: Andrew Walker reports: Issue 1: Users are always granted permissions to cd into a directory. The check for whether execute is present on […]

Read more
CHAT