FreeBSD 14

FreeBSD 14 — cdrdao — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — cdrdao — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: cdrdao — unspecified privilege escalation vulnerability Upstream summary: The developers of cdrdao report that there is a potential root exploit in the software. In order to be able to succesfully […]

Read more
FreeBSD 14 — py38-tuf — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py38-tuf — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: The Update Framwork — path traversal vulnerability Related CVEs: CVE-2021-41131 Upstream summary: NVD reports: python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and […]

Read more
FreeBSD 14 — php73-imap — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php73-imap — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php-imap — imap_open allows to run arbitrary shell commands via mailbox parameter Upstream summary: The PHP team reports: imap_open allows to run arbitrary shell commands via mailbox parameter. Table of […]

Read more
FreeBSD 14 — linux-f8-pango — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — linux-f8-pango — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pango — integer overflow Related CVEs: CVE-2009-1194 Upstream summary: oCERT reports: Pango suffers from a multiplicative integer overflow which may lead to a potentially exploitable, heap overflow depending on the […]

Read more
FreeBSD 14 — libpurple — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — libpurple — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libpurple/pidgin — multiple vulnerabilities Related CVEs: CVE-2009-1373 CVE-2009-1374 CVE-2009-1375 CVE-2009-1376 CVE-2009-2694 CVE-2010-0277 CVE-2010-0420 CVE-2010-0423  +11 more Upstream summary: The pidgin development team reports: . Table of contents Symptom & Impact […]

Read more
FreeBSD 14 — node_exporter — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — node_exporter — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: node_exporter — bypass security with cache poisoning Related CVEs: CVE-2022-46146 Upstream summary: Prometheus team reports: Prometheus and its exporters can be secured by a web.yml file that specifies usernames and […]

Read more
FreeBSD 14 — php71-mbstring — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php71-mbstring — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: oniguruma — multiple vulnerabilities Related CVEs: CVE-2017-9224 CVE-2017-9226 CVE-2017-9227 CVE-2017-9228 Upstream summary: the PHP project reports: A stack out-of-bounds read occurs in match_at() during regular expression searching. A logical error […]

Read more
FreeBSD 14 — rubygem-date — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rubygem-date — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-date — Regular Expression Denial of Service Vunlerability of Date Parsing Methods Related CVEs: CVE-2021-41817 Upstream summary: Stanislav Valkanov reports: Date's parsing methods including Date.parse are using Regexps internally, some […]

Read more
FreeBSD 14 — gitolite — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — gitolite — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gitolite — path traversal vulnerability Related CVEs: CVE-2012-4506 Upstream summary: Sitaram Chamarty reports: I'm sorry to say there is a potential path traversal vulnerability in v3. Thanks to Stephane Chazelas […]

Read more
FreeBSD 14 — py33-radicale — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py33-radicale — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: radicale — multiple vulnerabilities Related CVEs: CVE-2015-8747 CVE-2015-8748 Upstream summary: Radicale reports: The multifilesystem backend allows access to arbitrary files on all platforms. Prevent regex injection in rights management. Table […]

Read more
CHAT