FreeBSD

FreeBSD 14 — sdl_image — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — sdl_image — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sdl_image — buffer overflow vulnerabilities Related CVEs: CVE-2007-6697 CVE-2008-0544 Upstream summary: Secunia reports: Two vulnerabilities have been reported in SDL_image, which can be exploited by malicious people to cause a […]

Read more
FreeBSD 14 — unbound — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — unbound — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: unbound — Possible domain hijacking via promiscuous records in the authority section Related CVEs: CVE-2011-1922 CVE-2011-4528 CVE-2014-8602 CVE-2017-15105 CVE-2019-16866 CVE-2019-18934 CVE-2020-12662 CVE-2020-12663  +10 more Upstream summary: [email protected] reports: NLnet Labs […]

Read more
FreeBSD 14 — postgresql96-server — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — postgresql96-server — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgreSQL — Possible man-in-the-middle attacks Related CVEs: CVE-2016-5423 CVE-2016-5424 CVE-2017-15098 CVE-2017-15099 CVE-2017-7546 CVE-2017-7547 CVE-2017-7548 CVE-2018-1052  +11 more Upstream summary: The PostgreSQL Project reports: CVE-2021-23214: A man-in-the-middle with the ability to […]

Read more
FreeBSD 14 — aide — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — aide — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: aide — heap-based buffer overflow Related CVEs: CVE-2021-45417 Upstream summary: David Bouman reports: AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS […]

Read more
FreeBSD 14 — pspp — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — pspp — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pspp — multiple vulnerabilities Related CVEs: CVE-2017-10791 CVE-2017-10792 CVE-2017-12958 CVE-2017-12959 CVE-2017-12960 CVE-2017-12961 Upstream summary: CVE Details reports: There is an Integer overflow in the hash_int function of the libpspp library […]

Read more
FreeBSD 12 — py312-setuptools — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py312-setuptools — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 February 2025 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-setuptools — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Related CVEs: CVE-2025-47273 Upstream summary: https://github.com/pypa/setuptools/security/advisories/GHSA-5rjg-fvgr-3xxf reports: setuptools is a package that allows users to download, build, […]

Read more
FreeBSD 13 — step-certificates — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — step-certificates — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 February 2025 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: step-certificates — Authorization Bypass in ACME and SCEP Provisioners Related CVEs: CVE-2025-44005 Upstream summary: smallstep reports: An attacker can bypass authorization checks and force a Step CA ACME or SCEP […]

Read more
FreeBSD 14 — mathopd — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mathopd — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mathopd — directory traversal vulnerability Upstream summary: Michiel Boland reports: The software has a vulnerability that could lead to directory traversal if the '*' construct for mass virtual hosting is […]

Read more
FreeBSD 14 — kdeedu — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — kdeedu — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 February 2025 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: kstars — exploitable set-user-ID application fliccd Related CVEs: CVE-2005-0011 Upstream summary: A KDE Security Advisory explains: Overview KStars includes support for the Instrument Neutral Distributed Interface (INDI). The build system […]

Read more
CHAT