FreeBSD 14

FreeBSD 14 — git-lite — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — git-lite — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: git — Multiple vulnerabilities Related CVEs: CVE-2015-7545 CVE-2016-2324 CVE-2018-11233 CVE-2018-11235 CVE-2020-11008 CVE-2020-5260 CVE-2022-39253 CVE-2022-39260  +2 more Upstream summary: git developers reports: This update includes 2 security fixes: CVE-2023-25652: By feeding […]

Read more
FreeBSD 14 — php71-imap — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php71-imap — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php-imap — imap_open allows to run arbitrary shell commands via mailbox parameter Upstream summary: The PHP team reports: imap_open allows to run arbitrary shell commands via mailbox parameter. Table of […]

Read more
FreeBSD 14 — py32-radicale — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py32-radicale — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: radicale — multiple vulnerabilities Related CVEs: CVE-2015-8747 CVE-2015-8748 Upstream summary: Radicale reports: The multifilesystem backend allows access to arbitrary files on all platforms. Prevent regex injection in rights management. Table […]

Read more
FreeBSD 14 — junkbuster-zlib — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — junkbuster-zlib — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: junkbuster — heap corruption vulnerability and configuration modification vulnerability Related CVEs: CVE-2005-1108 CVE-2005-1109 Upstream summary: A Debian advisory reports: James Ranson discovered that an attacker can modify the referrer setting […]

Read more
FreeBSD 14 — pkcs11-helper — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — pkcs11-helper — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pkcs11-helper — deserialize buffer overflow Upstream summary: Alon Bar-Lev reports: util: fix deserialize buffer overflow. thanks to Aarnav Bos. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 14 — ghostscript-gpl-nox — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ghostscript-gpl-nox — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ghostscript — zseticcspace() function buffer overflow vulnerability Related CVEs: CVE-2008-0411 Upstream summary: Chris Evans from the Google Security Team reports: Severity: parsing of evil PostScript file will result in arbitrary […]

Read more
FreeBSD 14 — syncthing — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — syncthing — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: syncthing — crash due to malformed relay protocol message Related CVEs: CVE-2021-21404 Upstream summary: syncthing developers report: syncthing can be caused to crash and exit if sent a malformed relay […]

Read more
FreeBSD 14 — qt4-xml — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — qt4-xml — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: qt4-xml — XML Entity Expansion Denial of Service Related CVEs: CVE-2013-4549 Upstream summary: Richard J. Moore reports: QXmlSimpleReader in Qt versions prior to 5.2 supports expansion of internal entities in […]

Read more
FreeBSD 14 — wu-ftpd+ipv — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — wu-ftpd+ipv — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 June 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wu-ftpd — remote globbing DoS vulnerability Related CVEs: CVE-2004-0148 CVE-2005-0256 Upstream summary: An iDEFENSE Security Advisory reports: Remote exploitation of an input validation vulnerability in version 2.6.2 of WU-FPTD could […]

Read more
CHAT