FreeBSD

FreeBSD 14 — samba32-devel — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — samba32-devel — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: samba — potential leakage of arbitrary memory contents Related CVEs: CVE-2008-4314 Upstream summary: Samba Team reports: Samba 3.0.29 and beyond contain a change to deal with gcc 4 optimizations. Part […]

Read more
FreeBSD 14 — bld — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — bld — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fd_set — bitmap index overflow in multiple applications Upstream summary: 3APA3A reports: If programmer fails to check socket number before using select() or fd_set macros, it's possible to overwrite memory […]

Read more
FreeBSD 12 — R — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — R — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 April 2024 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: R — arbitrary code execution vulnerability Related CVEs: CVE-2024-27322 Upstream summary: HiddenLayer Research reports: Deserialization of untrusted data can occur in the R statistical programming language, enabling a maliciously crafted […]

Read more
FreeBSD 14 — evince — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — evince — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: evince and atril — command injection vulnerability in CBT handler Related CVEs: CVE-2006-5864 CVE-2017-1000083 Upstream summary: GNOME reports: The comic book backend in evince 3.24.0 (and earlier) is vulnerable to […]

Read more
FreeBSD 14 — gnupg — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — gnupg — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gnupg — AEAD key import overflow Related CVEs: CVE-2003-0971 CVE-2005-0366 CVE-2006-0049 CVE-2006-0455 CVE-2006-3082 CVE-2006-6235 CVE-2008-1530 CVE-2013-4402  +5 more Upstream summary: Importing an OpenPGP key having a preference list for AEAD […]

Read more
FreeBSD 14 — a2ps-a — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — a2ps-a — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: a2ps — insecure temporary file creation Related CVEs: CVE-2004-1170 CVE-2004-1377 Upstream summary: A Secunia Security Advisory reports that Javier Fernández-Sanguino Peña has found temporary file creation vulnerabilities in the fixps […]

Read more
FreeBSD 14 — bind — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — bind — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: DNSSEC validators — denial-of-service/CPU exhaustion from KeyTrap and NSEC3 vulnerabilities Related CVEs: CVE-2003-0914 CVE-2005-0033 CVE-2005-0034 CVE-2006-4095 CVE-2006-4096 CVE-2009-0696 CVE-2011-1910 CVE-2011-2464  +12 more Upstream summary: Simon Kelley reports: If DNSSEC validation […]

Read more
FreeBSD 14 — rabbitmq — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — rabbitmq — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: RabbitMQ — Denial of Service via improper input validation Related CVEs: CVE-2015-0862 CVE-2016-9877 CVE-2021-22116 Upstream summary: Jonathon Knudsen of Synopsys Cybersecurity Research Center reports: All versions prior to 3.8.16 are […]

Read more
FreeBSD 14 — py37-suds — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py37-suds — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-suds — vulnerable to symlink attacks Related CVEs: CVE-2013-2217 Upstream summary: SUSE reports: cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries […]

Read more
FreeBSD 14 — typo3-10-php — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — typo3-10-php — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 April 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: typo3 — XSS vulnerability in svg-sanitize Related CVEs: CVE-2020-11063 CVE-2020-11064 CVE-2020-11065 CVE-2020-11066 CVE-2020-11067 CVE-2020-11069 CVE-2020-15098 CVE-2020-15099  +1 more Upstream summary: The TYPO3 project reports: The SVG sanitizer library enshrined/svg-sanitize before […]

Read more
CHAT