FreeBSD

FreeBSD 12 — linux-c7-nss — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-c7-nss — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: nss — Use-after-free in TLS 1.2 generating handshake hashes Related CVEs: CVE-2016-2834 CVE-2017-5461 CVE-2017-5462 CVE-2017-7805 Upstream summary: Mozilla reports: During TLS 1.2 exchanges, handshake hashes are generated which point to […]

Read more
FreeBSD 12 — accountsservice — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — accountsservice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: AccountsService — Insufficient path check in user_change_icon_file_authorized_cb() Related CVEs: CVE-2018-14036 Upstream summary: NVD reports: Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check […]

Read more
FreeBSD 12 — libxfce4gui — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libxfce4gui — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xfce — multiple vulnerabilities Related CVEs: CVE-2007-6531 CVE-2007-6532 Upstream summary: Gentoo reports: A remote attacker could entice a user to install a specially crafted "rc" file to execute arbitrary code […]

Read more
FreeBSD 12 — py27-ecdsa — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py27-ecdsa — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: security/py-ecdsa — multiple issues Related CVEs: CVE-2019-14853 CVE-2019-14859 Upstream summary: py-ecdsa developers report: Fix CVE-2019-14853 – possible DoS caused by malformed signature decoding. Fix CVE-2019-14859 – signature malleability caused by […]

Read more
FreeBSD 12 — ja-linux-netscape — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ja-linux-netscape — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: firefox & mozilla — multiple vulnerabilities Related CVEs: CVE-2004-0762 CVE-2004-0765 CVE-2004-0904 CVE-2004-0905 CVE-2004-0908 CVE-2004-0909 CVE-2004-1156 CVE-2004-1157  +12 more Upstream summary: A Mozilla Foundation Security Advisory reports of multiple issues: Heap […]

Read more
FreeBSD 12 — msmtp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — msmtp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: msmtp — certificate-verification issue Related CVEs: CVE-2019-8337 Upstream summary: msmtp developers report: In msmtp 1.8.2, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. Table of contents […]

Read more
FreeBSD 12 — dojo — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — dojo — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dojo — cross-site scripting and other vulnerabilities Upstream summary: The Dojo Toolkit team reports: Some PHP files did not properly escape input. Some files could operate like "open redirects". A […]

Read more
FreeBSD 12 — apache22-itk-mpm — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — apache22-itk-mpm — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: apache22 — chunk header parsing defect Related CVEs: CVE-2012-0833 CVE-2012-2687 CVE-2012-3499 CVE-2012-4558 CVE-2013-1862 CVE-2013-1896 CVE-2013-5704 CVE-2013-6438  +5 more Upstream summary: Apache Foundation reports: CVE-2015-3183 core: Fix chunk header parsing defect. […]

Read more
FreeBSD 12 — gatekeeper — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — gatekeeper — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: GNU gatekeeper — denial of service Related CVEs: CVE-2012-3534 Upstream summary: Jan Willamowius reports: GNU Gatekeeper before 3.1 does not limit the number of connections to the status port, which […]

Read more
FreeBSD 12 — kamailio — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — kamailio — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 February 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: kamailio – buffer overflow Related CVEs: CVE-2016-2385 CVE-2018-8828 Upstream summary: A specially crafted REGISTER message with a malformed branch or From tag triggers an off-by-one heap-based buffer overflow in the […]

Read more
CHAT