FreeBSD

FreeBSD 14 — py31-django — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py31-django — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: django — multiple vulnerabilities Related CVEs: CVE-2009-3695 CVE-2010-3082 CVE-2014-0472 CVE-2014-0473 CVE-2014-0474 Upstream summary: The Django project reports: These releases address an unexpected code-execution issue, a caching issue which can expose […]

Read more
FreeBSD 14 — dovecot-pigeonhole — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — dovecot-pigeonhole — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dovecot-pigeonhole — Sieve excessive resource usage Related CVEs: CVE-2019-11500 CVE-2020-28200 Upstream summary: Dovecot team reports reports: Sieve interpreter is not protected against abusive scripts that claim excessive resource usage. Fixed […]

Read more
FreeBSD 14 — dnscrypt-proxy — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — dnscrypt-proxy — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dnscrypt-proxy — code execution Upstream summary: Frank Denis reports: Malformed packets could lead to denial of service or code execution. Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
FreeBSD 14 — phpSysInfo — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — phpSysInfo — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: phpsysinfo — url Cross-Site Scripting Related CVEs: CVE-2005-0869 CVE-2005-0870 Upstream summary: Doz reports: A Input passed in the URL to index.php is not properly sanitised before being returned to the […]

Read more
FreeBSD 14 — py38-Scrapy — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py38-Scrapy — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-Scrapy — DoS vulnerability Related CVEs: CVE-2017-14158 CVE-2022-0577 Upstream summary: kmike and nramirezuy report: Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files […]

Read more
FreeBSD 14 — apache13-ssl — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — apache13-ssl — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: apache — heap overflow in mod_proxy Related CVEs: CVE-2004-0492 Upstream summary: A buffer overflow exists in mod_proxy which may allow an attacker to launch local DoS attacks and possibly execute […]

Read more
FreeBSD 13 — gogs — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — gogs — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 December 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gogs — Multiple vulnerabilities Related CVEs: CVE-2022-1464 CVE-2024-39930 CVE-2024-39931 CVE-2024-39932 CVE-2024-39933 CVE-2024-44625 Upstream summary: [email protected] reports: CVE-2024-44625: Directory Traversal via the editFilePost function of internal/route/repo/editor.go. CVE-2024-39933: Gogs allows argument injection […]

Read more
FreeBSD 14 — polkit — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — polkit — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: polkit — Local Privilege Escalation Related CVEs: CVE-2015-3218 CVE-2015-3255 CVE-2015-3256 CVE-2015-4625 CVE-2021-3560 CVE-2021-4034 Upstream summary: Qualys reports: We discovered a Local Privilege Escalation (from any user to root) in polkit's […]

Read more
FreeBSD 14 — giflib — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — giflib — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: giflib — heap overflow Related CVEs: CVE-2015-7555 Upstream summary: Hans Jerry Illikainen reports: A heap overflow may occur in the giffix utility included in giflib-5.1.1 when processing records of the […]

Read more
FreeBSD 14 — py311-wagtail — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py311-wagtail — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-wagtail — stored XSS vulnerability Related CVEs: CVE-2023-28836 CVE-2023-28837 Upstream summary: A stored cross-site scripting (XSS) vulnerability exists on ModelAdmin views within the Wagtail admin interface. A user with a […]

Read more
CHAT