FreeBSD

FreeBSD 14 — usermin — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — usermin — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 October 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: webmin — unauthenticated remote code execution Related CVEs: CVE-2005-3912 CVE-2005-3962 CVE-2019-15107 Upstream summary: Joe Cooper reports: I've rolled out Webmin version 1.930 and Usermin version 1.780 for all repositories. This […]

Read more
FreeBSD 14 — apache+mod_ssl+mod_accel — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — apache+mod_ssl+mod_accel — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 October 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: apache — Prevent chunk-size integer overflow on platforms where sizeof(int) < sizeof(long) Related CVEs: CVE-2005-2088 CVE-2005-3352 CVE-2006-3747 Upstream summary: Apache ChangeLog reports: Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c […]

Read more
FreeBSD 14 — php80-kanboard — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php80-kanboard — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 October 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Kanboard — Multiple vulnerabilities Related CVEs: CVE-2023-32685 CVE-2023-33956 CVE-2023-33968 CVE-2023-33969 CVE-2023-33970 Upstream summary: Kanboard is project management software that focuses on the Kanban methodology. The last update includes 4 vulnerabilities: […]

Read more
FreeBSD 14 — lldpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — lldpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 October 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lldpd — Buffer overflow/Denial of service Related CVEs: CVE-2015-8011 CVE-2015-8012 Upstream summary: The lldpd developer Vincent Bernat reports: A buffer overflow may allow arbitrary code execution only if hardening was […]

Read more
FreeBSD 14 — ksh93-devel — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ksh93-devel — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 October 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ksh93 — certain environment variables interpreted as arithmetic expressions on startup, leading to code injection Upstream summary: Upstream ksh93 maintainer Siteshwar Vashisht reports: A flaw was found in the way […]

Read more
FreeBSD 14 — shadowsocks-libev — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — shadowsocks-libev — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 October 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: shadowsocks-libev — command injection via shell metacharacters Upstream summary: MITRE reports: Improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic. Table […]

Read more
FreeBSD 14 — p5-Config-IniFiles — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — p5-Config-IniFiles — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 October 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-Config-IniFiles — unsafe temporary file creation Related CVEs: CVE-2012-2451 Upstream summary: Unsafe Temporary file creation Config::IniFiles used a predictable name for its temporary file without opening it correctly. Table of […]

Read more
FreeBSD 14 — mozilla — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mozilla — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 11 October 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mozilla — multiple vulnerabilities Related CVEs: CVE-2004-0597 CVE-2004-0598 CVE-2004-0599 CVE-2004-0717 CVE-2004-0718 CVE-2004-0721 CVE-2004-0722 CVE-2004-0757  +12 more Upstream summary: [email protected] reports: Memory safety bugs present in Firefox 134 and Thunderbird 134. […]

Read more
FreeBSD 14 — py37-flask-security — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py37-flask-security — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 October 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-flask-security — user redirect to arbitrary URL vulnerability Related CVEs: CVE-2021-23385 Upstream summary: Snyk reports: This affects all versions of package Flask-Security. When using the `get_post_logout_redirect` and `get_post_login_redirect` functions, it […]

Read more
FreeBSD 14 — php56-ftp — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php56-ftp — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 October 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php5 — multiple vulnerabilities Related CVEs: CVE-2015-4643 CVE-2015-4644 Upstream summary: The PHP project reports: DOM and GD: Fixed bug #69719 (Incorrect handling of paths with NULs). FTP: Improved fix for […]

Read more
CHAT