FreeBSD 14

FreeBSD 14 — corkscrew — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — corkscrew — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: corkscrew — buffer overflow vulnerability Upstream summary: The affected corkscrew versions use sscanf calls without proper bounds checking. In the authentication file parsing routine this can cause an exploitable buffer […]

Read more
FreeBSD 14 — mod_security — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mod_security — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: www/mod_security — NULL pointer dereference DoS Related CVEs: CVE-2013-1915 CVE-2013-2765 Upstream summary: SecurityFocus reports: When ModSecurity receives a request body with a size bigger than the value set by the […]

Read more
FreeBSD 14 — ipsec-tools — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ipsec-tools — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ipsec-tools — remotely exploitable computational-complexity attack Related CVEs: CVE-2008-3651 CVE-2008-3652 CVE-2016-10396 Upstream summary: Robert Foggia via NetBSD GNATS reports: The ipsec-tools racoon daemon contains a remotely exploitable computational complexity attack […]

Read more
FreeBSD 14 — ruby — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ruby — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-resolv — Possible denial of service Related CVEs: CVE-2004-0755 CVE-2004-0983 CVE-2005-1992 CVE-2005-2337 CVE-2006-3694 CVE-2006-5467 CVE-2006-6303 CVE-2008-1447  +12 more Upstream summary: Manu reports: The vulnerability is caused by an insufficient check […]

Read more
Common Problems 122642

PF NAT Stops Working After Interface Address Change

🟠 High   ⏱ 5–30 min  Last verified: 15 May 2024 Affected versions: FreeBSD 14 📖 ~1 min read Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – Primary Fix Solution – Alternative Approaches Verification & Acceptance Criteria Rollback Plan Prevention & Hardening Related Errors & […]

Read more
FreeBSD 14 — ioquake3-devel — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ioquake3-devel — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: id Tech 3 — remote code execution vulnerability Related CVEs: CVE-2017-6903 Upstream summary: The content auto-download of id Tech 3 can be used to deliver maliciously crafted content, that triggers […]

Read more
FreeBSD 14 — pgbouncer — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — pgbouncer — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pgbouncer — failed auth_query lookup leads to connection as auth_user Related CVEs: CVE-2015-4054 CVE-2015-6817 Upstream summary: PgBouncer reports: New auth_user functionality introduced in 1.6 allows login as auth_user when client […]

Read more
FreeBSD 14 — pear-twig-twig — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — pear-twig-twig — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pear-twig — remote code execution Related CVEs: CVE-2015-7809 Upstream summary: Fabien Potencier reports: End users can craft valid Twig code that allows them to execute arbitrary code (RCEs) via the […]

Read more
FreeBSD 14 — py34-django-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py34-django-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: django — multiple vulnerabilities Related CVEs: CVE-2014-0480 CVE-2014-0481 CVE-2014-0482 CVE-2014-0483 CVE-2015-0219 CVE-2015-0220 CVE-2015-0221 CVE-2015-0222  +12 more Upstream summary: Tim Graham reports: Malicious redirect and possible XSS attack via user-supplied redirect […]

Read more
FreeBSD 14 — junkbuster — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — junkbuster — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: junkbuster — heap corruption vulnerability and configuration modification vulnerability Related CVEs: CVE-2005-1108 CVE-2005-1109 Upstream summary: A Debian advisory reports: James Ranson discovered that an attacker can modify the referrer setting […]

Read more
CHAT