FreeBSD

FreeBSD 12 — rubygem19-dragonfly — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rubygem19-dragonfly — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-dragonfly — arbitrary code execution Related CVEs: CVE-2013-1756 Upstream summary: Mark Evans reports: Unfortnately there is a security vulnerability in Dragonfly when used with Rails which would potentially allow an […]

Read more
FreeBSD 12 — ja-tdiary — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ja-tdiary — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 29 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tdiary — injection vulnerability Related CVEs: CVE-2006-6174 Upstream summary: An undisclosed eRuby injection vulnerability had been discovered in tDiary. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 12 — mod_auth_mellon — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mod_auth_mellon — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mod_auth_mellon — Redirect URL validation bypass Related CVEs: CVE-2019-13038 Upstream summary: Jakub Hrozek reports: Version 0.17.0 and older of mod_auth_mellon allows the redirect URL validation to be bypassed by specifying […]

Read more
FreeBSD 12 — p5-UI-Dialog — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — p5-UI-Dialog — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-UI-Dialog — shell command execution vulnerability Related CVEs: CVE-2008-7315 Upstream summary: Matthijs Kooijman reports: It seems that the whiptail, cdialog and kdialog backends apply some improper escaping in their shell […]

Read more
FreeBSD 12 — v — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — v — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: node, iojs, and v8 — denial of service Related CVEs: CVE-2011-4815 CVE-2011-4838 CVE-2011-5036 CVE-2011-5037 CVE-2015-5380 Upstream summary: node reports: This release of Node.js fixes a bug that triggers an out-of-band […]

Read more
FreeBSD 12 — aacplusenc — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — aacplusenc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: aacplusenc — denial of service Related CVEs: CVE-2017-14181 Upstream summary: Gentoo developers report: DeleteBitBuffer in libbitbuf/bitbuffer.c in mp4tools aacplusenc 0.17.5 allows remote attackers to cause a denial of service (invalid […]

Read more
FreeBSD 12 — htmldoc — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — htmldoc — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: HTMLDOC — buffer overflow issues when reading AFM files and parsing page sizes Upstream summary: Michael Sweet reports: HTMLDOC 1.8.28 fixes some known security issues and formatting bugs. Changes include: […]

Read more
FreeBSD 12 — xkbcomp — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — xkbcomp — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xkbcomp — Several vulnerabilities Related CVEs: CVE-2018-15859 CVE-2018-15861 CVE-2018-15863 Upstream summary: X.Org reports: Multiple issues have been found in xkbcomp that have been previously been published as CVEs in libxbkcommon. […]

Read more
FreeBSD 12 — xymon-server — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — xymon-server — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 26 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xymon-server — multiple vulnerabilities Related CVEs: CVE-2015-1430 CVE-2016-2054 CVE-2016-2055 CVE-2016-2056 CVE-2016-2057 CVE-2016-2058 CVE-2019-13273 CVE-2019-13274  +6 more Upstream summary: Japheth Cleaver reports: Several buffer overflows were reported by University of Cambridge […]

Read more
FreeBSD 12 — cross-binutils — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — cross-binutils — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 April 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: GNU binutils — multiple vulnerabilities Related CVEs: CVE-2014-8501 CVE-2014-8502 CVE-2014-8503 Upstream summary: US-CERT/NIST reports: The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause […]

Read more
CHAT