FreeBSD

FreeBSD 14 — php4-wddx — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php4-wddx — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2007-0905 CVE-2007-0906 CVE-2007-0907 CVE-2007-0908 CVE-2007-0909 CVE-2007-0910 CVE-2007-0988 CVE-2007-1001 Upstream summary: The PHP development team reports: Security Enhancements and Fixes in PHP 5.2.2 and PHP […]

Read more
FreeBSD 14 — py35-requests — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py35-requests — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: www/py-requests — Information disclosure vulnerability Upstream summary: The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which […]

Read more
FreeBSD 14 — portupgrade-devel — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — portupgrade-devel — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: portupgrade-devel — lack of distfile checksums Upstream summary: Ports security team reports: The portupgrade-devel port fetched directly from a git respository without checking against a known good SHA hash. This […]

Read more
FreeBSD 14 — py24-pylons — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py24-pylons — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-pylons — Path traversal bug Upstream summary: Pylons team reports: The error.py controller uses paste.fileapp to serve the static resources to the browser. The default error.py controller uses os.path.join to […]

Read more
FreeBSD 14 — imap-uw — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — imap-uw — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: imap-uw — University of Washington IMAP c-client Remote Format String Vulnerability Related CVEs: CVE-2005-0198 CVE-2005-2933 CVE-2008-5514 Upstream summary: SecurityFocus reports: University of Washington IMAP c-client is prone to a remote […]

Read more
FreeBSD 14 — py33-pygments — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py33-pygments — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pygments — shell injection vulnerability Related CVEs: CVE-2015-8557 Upstream summary: NVD reports: The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via […]

Read more
FreeBSD 14 — cabextract — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — cabextract — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: cabextract — directory traversal with UTF-8 symbols in filenames Related CVEs: CVE-2004-0916 CVE-2014-9556 CVE-2015-2060 Upstream summary: Cabextract ChangeLog reports: It was possible for cabinet files to extract to absolute file […]

Read more
FreeBSD 14 — gnomevfs — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — gnomevfs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gnomevfs — unsafe URI handling Related CVEs: CVE-2004-0494 Upstream summary: Alexander Larsson reports that some versions of gnome-vfs and MidnightCommander contain a number of `extfs' scripts that do not properly […]

Read more
FreeBSD 14 — wesnoth — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — wesnoth — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wesnoth — Code Injection vulnerability Related CVEs: CVE-2015-0844 CVE-2015-5069 CVE-2015-5070 CVE-2018-1999023 Upstream summary: shadowm reports: A severe bug was found in the game client which could allow a malicious user […]

Read more
FreeBSD 12 — postgresql13-server — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — postgresql13-server — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 February 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgreSQL — vulnerabilities Related CVEs: CVE-2021-23214 CVE-2021-23222 CVE-2021-3677 CVE-2022-1552 CVE-2024-10976 CVE-2024-10978 CVE-2024-7348 CVE-2025-4207  +3 more Upstream summary: PostgreSQL project reports: Tighten security checks in planner estimation functions. Prevent pg_dump scripts […]

Read more
CHAT