FreeBSD 14

FreeBSD 14 — libwww — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — libwww — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 May 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: expat — multiple vulnerabilities Related CVEs: CVE-2005-3183 CVE-2009-3560 CVE-2009-3720 CVE-2016-9063 CVE-2017-9233 Upstream summary: Mitre reports: An integer overflow during the parsing of XML using the Expat library. XML External Entity […]

Read more
FreeBSD 14 — fwbuilder — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — fwbuilder — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 May 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fwbuilder — security issue in temporary file handling Related CVEs: CVE-2009-4664 Upstream summary: Firewall Builder release notes reports: Vadim Kurland ([email protected]) reports: Fwbuilder and libfwbuilder 3.0.4 through to 3.0.6 generate […]

Read more
FreeBSD 14 — postgresql95-contrib — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — postgresql95-contrib — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 May 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgreSQL — minor security problems. Related CVEs: CVE-2016-2193 CVE-2016-3065 Upstream summary: PostgreSQL project reports: Security Fixes for RLS, BRIN This release closes security hole CVE-2016-2193 (https://access.redhat.com/security/cve/CVE-2016-2193), where a query plan […]

Read more
FreeBSD 14 — atheme-services — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — atheme-services — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 May 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: atheme-services — multiple vulnerabilities Related CVEs: CVE-2014-9773 CVE-2016-4478 Upstream summary: Mitre reports: modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping […]

Read more
FreeBSD 14 — postgresql-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — postgresql-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 May 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgreSQL server — Potentially allowing authenicated database users to see data that they shouldn't. Related CVEs: CVE-2005-0227 CVE-2005-0244 CVE-2005-0245 CVE-2005-0246 CVE-2005-0247 CVE-2006-0553 CVE-2006-2313 CVE-2006-2314  +12 more Upstream summary: PostgreSQL project […]

Read more
FreeBSD 14 — atutor — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — atutor — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 May 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: atutor — multiple vulnerabilities Upstream summary: ATutor reports: Security Fixes: Added a new layer of security over all php superglobals, fixed several XSS, CSRF, and SQL injection vulnerabilities. Table of […]

Read more
FreeBSD 14 — py39-OWSLib — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py39-OWSLib — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 May 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py39-OWSLib — arbitrary file read vulnerability Related CVEs: CVE-2023-27476 Upstream summary: Jorge Rosillo reports: OWSLib's XML parser (which supports both `lxml` and `xml.etree`) does not disable entity resolution for `lxml`, […]

Read more
FreeBSD 14 — postfix — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — postfix — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 May 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Postfix — memory corruption vulnerability Related CVEs: CVE-2011-0411 CVE-2011-1720 Upstream summary: The Postfix SMTP server has a memory corruption error, when the Cyrus SASL library is used with authentication mechanisms […]

Read more
CHAT