FreeBSD 14

FreeBSD 14 — py32-djblets — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py32-djblets — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-djblets — Self-XSS vulnerability Upstream summary: Djblets Release Notes reports: A recently-discovered vulnerability in the datagrid templates allows an attacker to generate a URL to any datagrid page containing malicious […]

Read more
FreeBSD 14 — htmldoc — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — htmldoc — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: HTMLDOC — buffer overflow issues when reading AFM files and parsing page sizes Upstream summary: Michael Sweet reports: HTMLDOC 1.8.28 fixes some known security issues and formatting bugs. Changes include: […]

Read more
FreeBSD 14 — patch — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — patch — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: patch — multiple vulnerabilities Related CVEs: CVE-2018-1000156 CVE-2018-6951 CVE-2018-6952 Upstream summary: NVD reports: An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a […]

Read more
FreeBSD 14 — fetchmail — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — fetchmail — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fetchmail — potential crash when authenticating to SMTP server Related CVEs: CVE-2003-0792 CVE-2005-2335 CVE-2005-3088 CVE-2005-4348 CVE-2006-0321 CVE-2006-5867 CVE-2006-5974 CVE-2007-1558  +11 more Upstream summary: Matthias Andree reports: fetchmail's SMTP client, when […]

Read more
FreeBSD 14 — py36-pyrad — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py36-pyrad — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pyrad — multiple vulnerabilities Related CVEs: CVE-2013-0294 CVE-2013-0342 Upstream summary: Nathaniel McCallum reports: packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which […]

Read more
FreeBSD 14 — py34-rsa — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py34-rsa — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-rsa — Bleichenbacher'06 signature forgery vulnerability Related CVEs: CVE-2016-1494 Upstream summary: Filippo Valsorda reports: python-rsa is vulnerable to a straightforward variant of the Bleichenbacher'06 attack against RSA signature verification with […]

Read more
FreeBSD 14 — py310-cryptography — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py310-cryptography — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-cryptography — includes a vulnerable copy of OpenSSL Related CVEs: CVE-2023-0286 CVE-2023-23931 Upstream summary: pyca/cryptography's wheels include a statically linked copy of OpenSSL. The versions of OpenSSL included in cryptography […]

Read more
FreeBSD 14 — telepathy-gabble — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — telepathy-gabble — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: telepathy-gabble — TLS verification bypass Related CVEs: CVE-2013-1431 Upstream summary: Simon McVittie reports: This release fixes a man-in-the-middle attack. If you use an unencrypted connection to a "legacy Jabber" (pre-XMPP) […]

Read more
FreeBSD 14 — samba — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — samba — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: samba — multiple vulnerabilities Related CVEs: CVE-2004-0082 CVE-2004-0600 CVE-2004-0686 CVE-2004-0807 CVE-2004-0808 CVE-2004-0815 CVE-2004-0882 CVE-2004-0930  +12 more Upstream summary: The Samba Team reports: CVE-2023-34967: Samba Spotlight mdssvc RPC Request Type Confusion […]

Read more
FreeBSD 14 — firefox-ja — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — firefox-ja — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mozilla — code execution via Quicktime media-link files Related CVEs: CVE-2006-4965 CVE-2006-6077 CVE-2007-0008 CVE-2007-0009 CVE-2007-0775 CVE-2007-0776 CVE-2007-0777 CVE-2007-0778  +11 more Upstream summary: The Mozilla Foundation reports a vulnerability within the […]

Read more
CHAT