FreeBSD 14

FreeBSD 14 — ghostscript9-x — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ghostscript9-x — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 March 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ghostscript — denial of service (crash) via crafted Postscript files Related CVEs: CVE-2015-3228 Upstream summary: MITRE reports: Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier […]

Read more
FreeBSD 14 — mod_jk — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mod_jk — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 March 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mod_jk — information disclosure Related CVEs: CVE-2007-0774 CVE-2007-1860 Upstream summary: Kazu Nambo reports: URL decoding the Apache webserver prior to decoding in the Tomcat server could pypass access control rules […]

Read more
FreeBSD 14 — kdebase-runtime — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — kdebase-runtime — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 March 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: KDE — multiple vulnerabilities Upstream summary: oCERT reports: Ark input sanitization errors: The KDE archiving tool, Ark, performs insufficient validation which leads to specially crafted archive files, using unknown MIME […]

Read more
FreeBSD 14 — habari — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — habari — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 March 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: habari — Cross-Site Scripting Vulnerability Related CVEs: CVE-2008-4601 Upstream summary: Secunia reports: Input passed via the "habari_username" parameter when logging in is not properly sanitised before being returned to the […]

Read more
FreeBSD 14 — lshell — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — lshell — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 March 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lshell — Shell autocomplete reveals forbidden directories Upstream summary: lshell reports: The autocomplete feature allows users to list directories, while they do not have access to those paths (issue #109). […]

Read more
FreeBSD 14 — sqlite — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — sqlite — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 March 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: SQLite < 3.50.3 — CWE-190 Integer Overflow or Wraparound in FTS5 module Related CVEs: CVE-2015-3414 CVE-2015-3415 CVE-2015-3416 CVE-2016-6153 CVE-2017-10989 CVE-2018-8740 CVE-2019-5018 CVE-2020-11655  +12 more Upstream summary: https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g reports: An integer […]

Read more
FreeBSD 14 — w3m-m17n-img — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — w3m-m17n-img — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 March 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: w3m — format string vulnerability Related CVEs: CVE-2006-6772 Upstream summary: An anonymous person reports: w3m-0.5.1 crashes when using the -dump or -backend options to open a HTTPS URL with a […]

Read more
FreeBSD 14 — py35-matrix-synapse — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py35-matrix-synapse — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 March 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-matrix-synapse — users of single-sign-on are vulnerable to phishing Related CVEs: CVE-2019-5885 Upstream summary: Matrix developers report: [The 1.11.1] release includes a security fix impacting installations using Single Sign-On (i.e. […]

Read more
FreeBSD 14 — subversion-lts — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — subversion-lts — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 March 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Subversion — Multiple vulnerabilities in server code Related CVEs: CVE-2021-28544 CVE-2022-24070 Upstream summary: Subversion project reports: Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization […]

Read more
CHAT