FreeBSD

FreeBSD 12 — grub2-bhyve — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — grub2-bhyve — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: grub2-bhyve — multiple privilege escalations Upstream summary: Reno Robert reports: FreeBSD uses a two-process model for running a VM. For booting non-FreeBSD guests, a modified grub-emu is used (grub-bhyve). Grub-bhyve […]

Read more
FreeBSD 12 — eperl — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — eperl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: eperl — Remote code execution Related CVEs: CVE-2001-0733 Upstream summary: David Madison reports: ePerl is a multipurpose Perl filter and interpreter program for Unix systems. The ePerl preprocessor contains an […]

Read more
FreeBSD 12 — vim6+ruby — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — vim6+ruby — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: vim6 — heap-based overflow while parsing shell metacharacters Related CVEs: CVE-2008-3432 Upstream summary: Description for CVE-2008-3432 says: Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and […]

Read more
FreeBSD 12 — xv-m17n — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — xv-m17n — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xv — exploitable buffer overflows Upstream summary: In a Bugtraq posting, infamous41md(at)hotpop.com reported: there are at least 5 exploitable buffer and heap overflows in the image handling code. this allows […]

Read more
FreeBSD 12 — gstreamer-plugins-good — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — gstreamer-plugins-good — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gstreamer-plugins-good — multiple memory overflows Related CVEs: CVE-2009-0386 CVE-2009-0387 CVE-2009-0397 Upstream summary: Secunia reports: Tobias Klein has reported some vulnerabilities in GStreamer Good Plug-ins, which can potentially be exploited by […]

Read more
FreeBSD 12 — mariadb-client — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mariadb-client — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL – Multiple vulnerabilities Related CVEs: CVE-2015-4792 CVE-2015-4802 CVE-2015-4807 CVE-2015-4815 CVE-2015-4826 CVE-2015-4830 CVE-2015-4836 CVE-2015-4858  +3 more Upstream summary: Oracle reports: Critical Patch Update: MySQL Server, version(s) 5.5.45 and prior, 5.6.26 […]

Read more
FreeBSD 12 — rar — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rar — password prompt buffer overflow vulnerability Related CVEs: CVE-2007-0855 Upstream summary: iDefense reports: Remote exploitation of a stack based buffer overflow vulnerability in RARLabs Unrar may allow an attacker […]

Read more
FreeBSD 12 — mod_pagespeed — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mod_pagespeed — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mod_pagespeed — critical cross-site scripting (XSS) vulnerability Related CVEs: CVE-2012-4001 CVE-2012-4360 CVE-2013-6111 Upstream summary: mod_pagespeed developers report: Various versions of mod_pagespeed are subject to critical cross-site scripting (XSS) vulnerability, CVE-2013-6111. […]

Read more
FreeBSD 12 — kdegraphics — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — kdegraphics — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xpdf — multiple remote Stream.CC vulnerabilities Related CVEs: CVE-2004-0888 CVE-2004-0889 CVE-2004-1125 CVE-2005-0064 CVE-2005-2097 CVE-2006-0301 CVE-2007-3387 CVE-2007-4352  +2 more Upstream summary: Secunia Research reports: Secunia Research has discovered some vulnerabilities in […]

Read more
FreeBSD 12 — GraphicsMagick — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — GraphicsMagick — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: GraphicsMagick — multiple vulnerabilities Related CVEs: CVE-2012-3438 CVE-2016-2317 CVE-2016-7800 CVE-2016-7996 CVE-2016-7997 CVE-2016-9830 CVE-2017-10794 CVE-2017-10799  +3 more Upstream summary: GraphicsMagick News: Read "Security Fixes:" section for details. Table of contents Symptom […]

Read more
CHAT