FreeBSD

FreeBSD 14 — openssl-beta-overwrite-base — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — openssl-beta-overwrite-base — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 September 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openssl — potential SSL 2.0 rollback Related CVEs: CVE-2005-2969 Upstream summary: Vulnerability: Such applications are affected if they use the option SSL_OP_MSIE_SSLV2_RSA_PADDING. This option is implied by use of SSL_OP_ALL, […]

Read more
FreeBSD 14 — py311-beaker — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py311-beaker — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 September 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-beaker — arbitrary code execution vulnerability Related CVEs: CVE-2013-7489 Upstream summary: matheusbrat reports: The Beaker library through 1.12.1 for Python is affected by deserialization of untrusted data, which could lead […]

Read more
FreeBSD 14 — sogo2-activesync — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — sogo2-activesync — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 September 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: SOGo — SAML user authentication impersonation Related CVEs: CVE-2021-33054 Upstream summary: sogo.nu reports: SOGo was not validating the signatures of any SAML assertions it received. This means any actor with […]

Read more
FreeBSD 14 — mcollective — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mcollective — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 September 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mcollective — cert valication issue Related CVEs: CVE-2014-3251 Upstream summary: Melissa Stone reports: The MCollective aes_security public key plugin does not correctly validate certs against the CA. By exploiting this […]

Read more
FreeBSD 14 — freetype — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — freetype — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 September 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: freetype2 — heap buffer overlfow Related CVEs: CVE-2006-0747 CVE-2006-1861 CVE-2006-3467 CVE-2007-2754 CVE-2008-1806 CVE-2008-1807 CVE-2008-1808 CVE-2009-0946  +12 more Upstream summary: The freetype project reports: A heap buffer overflow has been found […]

Read more
FreeBSD 14 — fswiki — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — fswiki — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 September 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fswiki — XSS vulnerability Related CVEs: CVE-2005-1799 Upstream summary: JVN reports: FreeStyleWiki has XSS vulnerability. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
FreeBSD 14 — logstash — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — logstash — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 September 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: logstash — password disclosure vulnerability Related CVEs: CVE-2014-3120 CVE-2014-4326 CVE-2015-4152 CVE-2015-5378 Upstream summary: Logstash developers report: Passwords Printed in Log Files under Some Conditions It was discovered that, in Logstash […]

Read more
FreeBSD 14 — leafnode — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — leafnode — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 24 September 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: leafnode — denial of service vulnerability Related CVEs: CVE-2002-1661 CVE-2003-0744 CVE-2004-2068 CVE-2005-1453 CVE-2005-1911 Upstream summary: Matthias Andree reports: A vulnerability was found in the fetchnews program (the NNTP client) that […]

Read more
FreeBSD 14 — shibboleth-idp — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — shibboleth-idp — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 September 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: security/shibboleth-idp — CAS service SSRF Upstream summary: Shibboleth Developers report: The Identity Provider's CAS support relies on a function in the Spring Framework to parse CAS service URLs and append […]

Read more
FreeBSD 14 — wzdftpd — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — wzdftpd — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 September 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wzdftpd — remote DoS Upstream summary: wzdftpd contains a potential remote Denial-of-Service. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step Diagnosis Solution – […]

Read more
CHAT