FreeBSD

FreeBSD 12 — varnish — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — varnish — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 9 September 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Vinyl/Varnish — HTTP/2 parsing deficiency Related CVEs: CVE-2013-4484 CVE-2017-8807 CVE-2022-23959 CVE-2023-43622 CVE-2023-44487 CVE-2025-30346 CVE-2025-8671 Upstream summary: Vinyl Development Team reports: A deficiency in HTTP/2 request parsing can be exploited to […]

Read more
FreeBSD 14 — p5-Crypt-CBC — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — p5-Crypt-CBC — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 8 September 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-Crypt-CBC — Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Related CVEs: CVE-2025-2814 Upstream summary: Lib-Crypt-CBC project reports: Crypt::CBC versions between 1.21 and 3.05 for Perl may use the rand() […]

Read more
FreeBSD 14 — thunderbird-esr — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — thunderbird-esr — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 September 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Mozilla — Memory safety bugs Related CVEs: CVE-2025-8027 CVE-2025-8028 CVE-2025-8029 CVE-2025-8030 CVE-2025-8031 CVE-2025-8032 CVE-2025-8033 CVE-2025-8034  +7 more Upstream summary: Mozilla reports: Memory safety bugs present in Firefox ESR, Firefox ESR, […]

Read more
FreeBSD 14 — linux-rl9-sqlite — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — linux-rl9-sqlite — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 September 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sqlite — Integer Truncation on SQLite Related CVEs: CVE-2024-0232 CVE-2025-6965 Upstream summary: [email protected] reports: There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could […]

Read more
FreeBSD 12 — Thunderbird — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — Thunderbird — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 September 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Mozilla — Sandbox escape Related CVEs: CVE-2025-14321 CVE-2025-14322 Upstream summary: https://bugzilla.mozilla.org/show_bug.cgi?id=1996473 reports: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Table of contents Symptom & Impact […]

Read more
FreeBSD 14 — py312-setuptools — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py312-setuptools — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 September 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-setuptools — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Related CVEs: CVE-2025-47273 Upstream summary: https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf reports: setuptools is a package that allows users to download, build, […]

Read more
FreeBSD 12 — valkey — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — valkey — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 4 September 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: redis,valkey — Out of bound read due to a bug in LUA Related CVEs: CVE-2024-31227 CVE-2024-31228 CVE-2024-31449 CVE-2024-46981 CVE-2024-51741 CVE-2025-21605 CVE-2025-27151 CVE-2025-32023  +5 more Upstream summary: redis reports: An authenticated […]

Read more
FreeBSD 13 — py312-dj51-social-auth-app-django — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py312-dj51-social-auth-app-django — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 September 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-social-auth-app-django — Unsafe account association Related CVEs: CVE-2025-61783 Upstream summary: Michal Čihař reports: Upon authentication, the user could be associated by e-mail even if the associate_by_email pipeline was not included. […]

Read more
FreeBSD 12 — sudo-rs — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — sudo-rs — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 September 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sudo-rs — Authenticating user not recorded properly in timestamp Related CVEs: CVE-2025-64170 CVE-2025-64517 Upstream summary: Trifecta Tech Foundation reports: With Defaults targetpw (or Defaults rootpw) enabled, the password of the […]

Read more
FreeBSD 13 — mod_http — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mod_http — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 September 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mod_http2 — Multiple vulnerabilities Related CVEs: CVE-2020-11984 CVE-2020-11993 CVE-2020-9490 CVE-2024-24795 CVE-2024-27316 CVE-2024-38709 CVE-2025-49630 CVE-2025-53020 Upstream summary: The mod_http2 project reports: a client can increase memory consumption for a HTTP/2 connection […]

Read more
CHAT