FreeBSD

FreeBSD 14 — distcc — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — distcc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: distcc — incorrect parsing of IP access control rules Related CVEs: CVE-2004-0601 Upstream summary: Fix bug that might cause IP-based access control rules not to be interpreted correctly on 64-bit […]

Read more
FreeBSD 14 — py27-gunicorn — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py27-gunicorn — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-gunicorn — CWE-113 vulnerability Related CVEs: CVE-2018-1000164 Upstream summary: Everardo reports: gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in process_headers function in […]

Read more
FreeBSD 14 — bash-static — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — bash-static — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bash — remote code execution Related CVEs: CVE-2014-6271 CVE-2014-6277 CVE-2014-6278 CVE-2014-7169 CVE-2014-7186 CVE-2014-7187 Upstream summary: Note that this is different than the public "Shellshock" issue. Specially crafted environment variables could […]

Read more
FreeBSD 14 — gcab — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — gcab — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gcab — stack overflow Related CVEs: CVE-2018-5345 Upstream summary: Upstream reports: A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash […]

Read more
FreeBSD 14 — globus — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — globus — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: globus — Multiple tmpfile races Related CVEs: CVE-2006-4232 CVE-2006-4233 Upstream summary: The Globus Alliance reports: The proxy generation tool (grid-proxy-init) creates the file, secures the file to provide access only […]

Read more
FreeBSD 14 — librsync — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — librsync — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: librsync — collision vulnerability Related CVEs: CVE-2014-8242 Upstream summary: Michael Samuel reports: librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers […]

Read more
FreeBSD 14 — rubygem-rdoc — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rubygem-rdoc — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: RDoc — command injection vulnerability Related CVEs: CVE-2012-6708 CVE-2015-9251 CVE-2021-31799 Upstream summary: Alexandr Savca reports: RDoc used to call Kernel#open to open a local file. If a Ruby project has […]

Read more
FreeBSD 14 — linux-c7-tiff — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — linux-c7-tiff — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tiff — multiple vulnerabilities Related CVEs: CVE-2015-8870 CVE-2016-5652 CVE-2016-9533 CVE-2016-9534 CVE-2016-9535 CVE-2016-9536 CVE-2016-9537 CVE-2016-9540  +12 more Upstream summary: NVD reports: Please reference CVE/URL list for details Table of contents Symptom […]

Read more
FreeBSD 14 — py36-pysaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py36-pysaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pysaml2 — multiple vulnerabilities Related CVEs: CVE-2021-21238 CVE-2021-21239 Upstream summary: pysaml2 Releases: Fix processing of invalid SAML XML documents – CVE-2021-21238 Fix unspecified xmlsec1 key-type preference – CVE-2021-21239 Table of […]

Read more
FreeBSD 14 — linux_base-c6_ — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — linux_base-c6_ — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 December 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: glibc — getaddrinfo stack-based buffer overflow Related CVEs: CVE-2015-7547 Upstream summary: Fabio Olive Leite reports: A stack-based buffer overflow was found in libresolv when invoked from nss_dns, allowing specially crafted […]

Read more
CHAT