FreeBSD 14

FreeBSD 14 — rockdodger — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rockdodger — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rockdodger — buffer overflows Upstream summary: The environment variable HOME is copied without regard to buffer size, which can be used to gain elevated privilege if the binary is installed […]

Read more
FreeBSD 14 — rubygem-actionview — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rubygem-actionview — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Rails — XSS vulnerabilities Related CVEs: CVE-2015-7576 CVE-2015-7577 CVE-2015-7581 CVE-2016-0751 CVE-2016-0752 CVE-2016-0753 CVE-2016-2097 CVE-2016-2098  +12 more Upstream summary: Ruby on Rails blog: This is an announcement to let you know […]

Read more
FreeBSD 14 — cpu-microcode-intel — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — cpu-microcode-intel — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Intel CPUs — multiple vulnerabilities Related CVEs: CVE-2023-22655 CVE-2023-28746 CVE-2023-38575 CVE-2023-39368 CVE-2023-42667 CVE-2023-43490 CVE-2023-43758 CVE-2023-45733  +12 more Upstream summary: Intel reports: A potential security vulnerability in some Intel Processors may […]

Read more
FreeBSD 14 — tauthon — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — tauthon — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tauthon — Regular Expression Denial of Service Related CVEs: CVE-2020-8492 Upstream summary: The :class:`~urllib.request.AbstractBasicAuthHandler` class of the :mod:`urllib.request` module uses an inefficient regular expression which can be exploited by an […]

Read more
FreeBSD 14 — bzip — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — bzip — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bzip2 — multiple issues Related CVEs: CVE-2005-0953 CVE-2005-1260 CVE-2008-1372 CVE-2010-0405 CVE-2016-3189 CVE-2019-12900 Upstream summary: bzip2 developers reports: CVE-2016-3189 – Fix use-after-free in bzip2recover (Jakub Martisko) CVE-2019-12900 – Detect out-of-range nSelectors […]

Read more
FreeBSD 14 — openjph — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — openjph — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenJPH < 0.24.5 — multiple vulnerabilities Upstream summary: Aous Naman reports several vulnerabilities fixed in OpenJPH versions up to 0.24.5 and credits Cary Phillips for reporting them from the OSS-fuzz […]

Read more
FreeBSD 14 — cloud-init — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — cloud-init — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: cloud-init — sensitive data exposure in cloud-init logs Related CVEs: CVE-2023-1786 Upstream summary: [email protected] reports: Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could […]

Read more
FreeBSD 14 — eGroupWare — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — eGroupWare — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pear-XML_RPC — remote PHP code injection vulnerability Related CVEs: CVE-2005-2498 Upstream summary: A Hardened-PHP Project Security Advisory reports: When the library parses XMLRPC requests/responses, it constructs a string of PHP […]

Read more
FreeBSD 14 — eog — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — eog — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: eog — out-of-bounds write Related CVEs: CVE-2016-6855 Upstream summary: Felix Riemann reports: CVE-2016-6855 out-of-bounds write in eog 3.10.2. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis […]

Read more
FreeBSD 14 — py33-cryptography — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py33-cryptography — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 January 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-cryptography — vulnerable HKDF key generation Related CVEs: CVE-2016-9243 Upstream summary: Alex Gaynor reports: Fixed a bug where “HKDF“ would return an empty byte-string if used with a “length“ less […]

Read more
CHAT