FreeBSD 14

FreeBSD 14 — imap-uw — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — imap-uw — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: imap-uw — University of Washington IMAP c-client Remote Format String Vulnerability Related CVEs: CVE-2005-0198 CVE-2005-2933 CVE-2008-5514 Upstream summary: SecurityFocus reports: University of Washington IMAP c-client is prone to a remote […]

Read more
FreeBSD 14 — py33-pygments — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py33-pygments — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pygments — shell injection vulnerability Related CVEs: CVE-2015-8557 Upstream summary: NVD reports: The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via […]

Read more
FreeBSD 14 — cabextract — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — cabextract — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: cabextract — directory traversal with UTF-8 symbols in filenames Related CVEs: CVE-2004-0916 CVE-2014-9556 CVE-2015-2060 Upstream summary: Cabextract ChangeLog reports: It was possible for cabinet files to extract to absolute file […]

Read more
FreeBSD 14 — gnomevfs — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — gnomevfs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gnomevfs — unsafe URI handling Related CVEs: CVE-2004-0494 Upstream summary: Alexander Larsson reports that some versions of gnome-vfs and MidnightCommander contain a number of `extfs' scripts that do not properly […]

Read more
FreeBSD 14 — wesnoth — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — wesnoth — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wesnoth — Code Injection vulnerability Related CVEs: CVE-2015-0844 CVE-2015-5069 CVE-2015-5070 CVE-2018-1999023 Upstream summary: shadowm reports: A severe bug was found in the game client which could allow a malicious user […]

Read more
FreeBSD 14 — lasso — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — lasso — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lasso — signature checking failure Related CVEs: CVE-2021-28091 Upstream summary: entrouvert reports: When AuthnResponse messages are not signed (which is permitted by the specifiation), all assertion's signatures should be checked, […]

Read more
FreeBSD 14 — bastillion — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — bastillion — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bastillion — log4j vulnerability Related CVEs: CVE-2021-44228 Upstream summary: FreeBSD port maintainer reports: Bastillion uses log4j. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage […]

Read more
FreeBSD 14 — openvpn-devel — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — openvpn-devel — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenVPN — avoid buffer overread parsing routes or endpoints Related CVEs: CVE-2008-3459 CVE-2020-11810 CVE-2023-46849 CVE-2023-46850 CVE-2025-10680 CVE-2025-12106 CVE-2025-13086 CVE-2025-2704 Upstream summary: Mikhail Khachaiants reports: socket: reject mismatched address family in […]

Read more
FreeBSD 14 — rubygem19-json — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rubygem19-json — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Ruby — Denial of Service and Unsafe Object Creation Vulnerability in JSON Related CVEs: CVE-2013-0269 Upstream summary: Aaron Patterson reports: When parsing certain JSON documents, the JSON gem can be […]

Read more
FreeBSD 14 — rubygem20-ruby_parser — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rubygem20-ruby_parser — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-ruby_parser — insecure tmp file usage Related CVEs: CVE-2013-0162 Upstream summary: Michael Scherer reports: This is a relatively minor tmp file usage issue. Table of contents Symptom & Impact Environment […]

Read more
CHAT