FreeBSD

FreeBSD 14 — linux-c7-libxslt — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — linux-c7-libxslt — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 June 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libxslt — multiple vulnerabilities Related CVEs: CVE-2025-11731 CVE-2025-7424 CVE-2025-7425 CVE-2025-9714 Upstream summary: Alan Coopersmith reports: On 6/16/25 15:12, Alan Coopersmith wrote: BTW, users of libxml2 may also be using its […]

Read more
FreeBSD 14 — gstreamer1-rtsp-server — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — gstreamer1-rtsp-server — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 June 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gstreamer1-rtsp-server — Potential Denial-of-Service (DoS) with specially crafted client requests Related CVEs: CVE-2024-44331 Upstream summary: Qingpeng Du reports: A series of specially crafted client requests during streaming setup (post client […]

Read more
FreeBSD 12 — py39-matrix-synapse — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py39-matrix-synapse — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 June 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-matrix-synapse — federation denial of service via malformed events Related CVEs: CVE-2020-26257 CVE-2020-26891 CVE-2021-29471 CVE-2021-39163 CVE-2021-39164 CVE-2021-41281 CVE-2022-31052 CVE-2024-31208  +7 more Upstream summary: element-hq/synapse developers report: A malicious server can […]

Read more
FreeBSD 14 — vim — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — vim — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 June 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: vim — potential data loss with zip.vim and specially crafted zip files Related CVEs: CVE-2004-1138 CVE-2005-2368 CVE-2007-2953 CVE-2008-2712 CVE-2008-3076 CVE-2008-3432 CVE-2016-1248 CVE-2025-27423  +1 more Upstream summary: Vim reports: See https://github.com/vim/vim/security/advisories/GHSA-693p-m996-3rmf […]

Read more
FreeBSD 14 — screen — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — screen — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 June 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: screen — multiple vulnerabilities Related CVEs: CVE-2006-4573 CVE-2015-6806 CVE-2025-23395 CVE-2025-46802 CVE-2025-46803 CVE-2025-46804 CVE-2025-46805 Upstream summary: The screen project reports: Multiple security issues in screen. Table of contents Symptom & Impact […]

Read more
FreeBSD 12 — glpi — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — glpi — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 31 May 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: glpi-project — GLPI multiple vulnerabilities Related CVEs: CVE-2011-2720 CVE-2019-13239 CVE-2019-14666 CVE-2020-11031 CVE-2020-11032 CVE-2020-11033 CVE-2020-11034 CVE-2020-11035  +12 more Upstream summary: [email protected] reports: CVE-2024-11955: A vulnerability was found in GLPI up to […]

Read more
FreeBSD 12 — py39-social-auth-app-django — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py39-social-auth-app-django — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 May 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-social-auth-app-django — Unsafe account association Related CVEs: CVE-2024-32879 CVE-2025-61783 Upstream summary: Michal Čihař reports: Upon authentication, the user could be associated by e-mail even if the associate_by_email pipeline was not […]

Read more
FreeBSD 12 — py38-spotipy — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py38-spotipy — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 May 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Spotipy — Spotipy's cache file, containing spotify auth token, is created with overly broad permissions Related CVEs: CVE-2023-23608 CVE-2025-27154 Upstream summary: [email protected] reports: Spotipy is a lightweight Python library for […]

Read more
FreeBSD 14 — xorg-nextserver — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — xorg-nextserver — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 30 May 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xorg server — Multiple vulnerabilities Related CVEs: CVE-2023-6816 CVE-2024-0229 CVE-2024-21885 CVE-2024-21886 CVE-2024-31080 CVE-2024-31081 CVE-2024-31083 CVE-2025-26594  +12 more Upstream summary: The X.Org project reports: CVE-2025-49176: Integer overflow in Big Requests Extension […]

Read more
FreeBSD 13 — p5-Authen-SASL — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — p5-Authen-SASL — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 30 May 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-Authen-SASL — Insecure source of randomness Related CVEs: CVE-2025-40918 Upstream summary: p5-Authen-SASL project reports: Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is […]

Read more
CHAT