FreeBSD 14

FreeBSD 14 — pyblosxom — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — pyblosxom — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pyblosxom — atom flavor multiple XML injection vulnerabilities Upstream summary: Security Focus reports: PyBlosxom is prone to multiple XML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before […]

Read more
FreeBSD 14 — linux-f10-flashplugin — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — linux-f10-flashplugin — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: flash — multiple vulnerabilities Related CVEs: CVE-2008-4546 CVE-2009-3793 CVE-2009-3794 CVE-2009-3796 CVE-2009-3797 CVE-2009-3798 CVE-2009-3799 CVE-2009-3800  +12 more Upstream summary: Adobe reports: These updates resolve type confusion vulnerabilities that could lead to […]

Read more
FreeBSD 14 — syslog-ng — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — syslog-ng — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: syslog-ng2 — startup directory leakage in the chroot environment Related CVEs: CVE-2008-5110 Upstream summary: Florian Grandel reports: I have not had the time to analyze all of syslog-ng code. But […]

Read more
FreeBSD 14 — pngcrush — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — pngcrush — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pngcrush — libpng Uninitialised Pointer Arrays Vulnerability Related CVEs: CVE-2009-0040 Upstream summary: Secunia reports: A vulnerability has been reported in Pngcrush, which can be exploited by malicious people to potentially […]

Read more
FreeBSD 14 — php80-composer — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php80-composer — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Remote Code Execution via web-accessible composer Related CVEs: CVE-2022-24828 CVE-2023-43655 Upstream summary: Composer project reports: Description: Users publishing a composer.phar to a public web-accessible server where the composer.phar can be […]

Read more
FreeBSD 14 — scponly — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — scponly — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: scponly — local privilege escalation exploits Upstream summary: Max Vozeler reports: If ALL the following conditions are true, administrators using scponly-4.1 or older may be at risk of a local […]

Read more
FreeBSD 14 — rawstudio — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rawstudio — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dcraw — integer overflow condition Related CVEs: CVE-2015-3885 Upstream summary: ocert reports: The dcraw tool, as well as several other projects re-using its code, suffers from an integer overflow condition […]

Read more
FreeBSD 14 — gd — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — gd — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libgd — integer overflow which could lead to heap buffer overflow Related CVEs: CVE-2004-0990 CVE-2007-3472 CVE-2007-3473 CVE-2007-3474 CVE-2007-3475 CVE-2007-3476 CVE-2007-3477 CVE-2007-3478  +5 more Upstream summary: LibGD reports: An integer overflow […]

Read more
FreeBSD 14 — vte — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — vte — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: vte — Classic terminal title set+query attack Related CVEs: CVE-2010-2713 Upstream summary: Kees Cook reports: Janne Snabb discovered that applications using VTE, such as gnome-terminal, did not correctly filter window […]

Read more
FreeBSD 14 — torrentflux — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — torrentflux — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: torrentflux — User-Agent XSS Vulnerability Related CVEs: CVE-2006-5227 Upstream summary: Steven Roddis reports that User-Agent string is not properly escaped when handled by torrentflux. This allows for arbitrary code insertion. […]

Read more
CHAT