FreeBSD 14

FreeBSD 14 — openfire — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — openfire — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Openfire administration console authentication bypass Related CVEs: CVE-2008-1728 CVE-2008-6508 CVE-2008-6509 CVE-2008-6510 CVE-2008-6511 CVE-2009-0496 CVE-2009-0497 CVE-2009-1595  +2 more Upstream summary: [email protected] reports: Openfire's administrative console, a web-based application, was found to […]

Read more
FreeBSD 14 — ghostscript9-base — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ghostscript9-base — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ghostscript — denial of service (crash) via crafted Postscript files Related CVEs: CVE-2015-3228 Upstream summary: MITRE reports: Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier […]

Read more
FreeBSD 14 — kwebkitpart — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — kwebkitpart — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: kwebkitpart, kde-runtime — insufficient input validation Related CVEs: CVE-2014-8600 Upstream summary: Albert Aastals Cid reports: kwebkitpart and the bookmarks:// io slave were not sanitizing input correctly allowing to some javascript […]

Read more
FreeBSD 14 — kronolith — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — kronolith — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: kronolith — arbitrary local file inclusion vulnerability Upstream summary: iDefense Labs reports: Remote exploitation of a design error in Horde's Kronolith could allow an authenticated web mail user to execute […]

Read more
FreeBSD 14 — procmail — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — procmail — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: procmail — Heap-based buffer overflow Related CVEs: CVE-2017-16844 Upstream summary: MITRE reports: A remote attacker could use a flaw to cause formail to crash, resulting in a denial of service […]

Read more
FreeBSD 14 — py33-graphite-web — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py33-graphite-web — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-graphite-web — Multiple vulnerabilities Related CVEs: CVE-2013-5093 Upstream summary: Graphite developers report: This release contains several security fixes for cross-site scripting (XSS) as well as a fix for a remote-execution […]

Read more
FreeBSD 14 — libtomcrypt — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — libtomcrypt — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libtomcrypt — weak signature scheme with ECC keys Upstream summary: The Secure Science Corporation reports that libtomcrypt is vulnerable to a weak signature scheme. This allows an attacker to create […]

Read more
FreeBSD 14 — nextcloud-calendar — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — nextcloud-calendar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Nextcloud Calendar — SMTP Command Injection Related CVEs: CVE-2022-24838 Upstream summary: reports: SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the […]

Read more
FreeBSD 14 — vim-console — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — vim-console — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Vim/NeoVim — Security vulnerability Related CVEs: CVE-2004-1138 CVE-2005-2368 CVE-2007-2953 CVE-2008-2712 CVE-2008-3076 CVE-2016-1248 Upstream summary: Security releases for Vim/NeoVim: Sandbox escape allows for arbitrary code execution. Table of contents Symptom & […]

Read more
FreeBSD 14 — monitorix — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — monitorix — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: monitorix — serious bug in the built-in HTTP server Upstream summary: Monitorix Project reports: A serious bug in the built-in HTTP server. It was discovered that the handle_request() routine did […]

Read more
CHAT