FreeBSD

FreeBSD 14 — php80-composer — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php80-composer — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Remote Code Execution via web-accessible composer Related CVEs: CVE-2022-24828 CVE-2023-43655 Upstream summary: Composer project reports: Description: Users publishing a composer.phar to a public web-accessible server where the composer.phar can be […]

Read more
FreeBSD 14 — scponly — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — scponly — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: scponly — local privilege escalation exploits Upstream summary: Max Vozeler reports: If ALL the following conditions are true, administrators using scponly-4.1 or older may be at risk of a local […]

Read more
FreeBSD 13 — py310-borgbackup — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py310-borgbackup — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Borg (Backup) — flaw in cryptographic authentication scheme in Borg allowed an attacker to fake archives and indirectly cause backup data loss. Related CVEs: CVE-2023-36811 Upstream summary: Thomas Waldmann reports: […]

Read more
FreeBSD 14 — rawstudio — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rawstudio — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dcraw — integer overflow condition Related CVEs: CVE-2015-3885 Upstream summary: ocert reports: The dcraw tool, as well as several other projects re-using its code, suffers from an integer overflow condition […]

Read more
FreeBSD 14 — gd — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — gd — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libgd — integer overflow which could lead to heap buffer overflow Related CVEs: CVE-2004-0990 CVE-2007-3472 CVE-2007-3473 CVE-2007-3474 CVE-2007-3475 CVE-2007-3476 CVE-2007-3477 CVE-2007-3478  +5 more Upstream summary: LibGD reports: An integer overflow […]

Read more
FreeBSD 14 — vte — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — vte — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: vte — Classic terminal title set+query attack Related CVEs: CVE-2010-2713 Upstream summary: Kees Cook reports: Janne Snabb discovered that applications using VTE, such as gnome-terminal, did not correctly filter window […]

Read more
FreeBSD 13 — postgresql-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — postgresql-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgreSQL server — Potentially allowing authenicated database users to see data that they shouldn't. Related CVEs: CVE-2005-0227 CVE-2005-0244 CVE-2005-0245 CVE-2005-0246 CVE-2005-0247 CVE-2006-0553 CVE-2006-2313 CVE-2006-2314  +12 more Upstream summary: PostgreSQL project […]

Read more
FreeBSD 14 — torrentflux — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — torrentflux — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: torrentflux — User-Agent XSS Vulnerability Related CVEs: CVE-2006-5227 Upstream summary: Steven Roddis reports that User-Agent string is not properly escaped when handled by torrentflux. This allows for arbitrary code insertion. […]

Read more
FreeBSD 14 — openvpn-auth-ldap — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — openvpn-auth-ldap — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: security/openvpn-auth-ldap — Fix buffer overflow in challenge/response Related CVEs: CVE-2024-28820 Upstream summary: Graham Northup reports: A buffer overflow in extract_openvpn_cr allows attackers with a valid LDAP username and who can […]

Read more
FreeBSD 14 — varnish-libvmod-digest — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — varnish-libvmod-digest — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 May 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: www/varnish-libvmod-digest — base64 decoding vulnerability Related CVEs: CVE-2023-41104 Upstream summary: varnish developers report: Common usage of vmod-digest is for basic HTTP authentication, in which case it may be possible for […]

Read more
CHAT