FreeBSD

FreeBSD 14 — py310-fail2ban — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py310-fail2ban — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fail2ban — possible RCE vulnerability in mailing action using mailutils Related CVEs: CVE-2021-32749 Upstream summary: Jakub Żoczek reports: Command mail from mailutils package used in mail actions like mail-whois can […]

Read more
FreeBSD 14 — ruby25-gems — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ruby25-gems — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: RubyGems — multiple vulnerabilities Related CVEs: CVE-2019-8320 CVE-2019-8321 CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325 Upstream summary: RubyGems Security Advisories: CVE-2019-8320: Delete directory using symlink when decompressing tar CVE-2019-8321: Escape sequence injection vulnerability […]

Read more
FreeBSD 14 — php70-bcmath — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php70-bcmath — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2016-3074 Upstream summary: The PHP Group reports: BCMath: Fixed bug #72093 (bcpowmod accepts negative scale and corrupts _one_ definition). Exif: Fixed bug #72094 (Out […]

Read more
FreeBSD 14 — py35-yaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py35-yaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-yaml — FullLoader (still) exploitable for arbitrary command execution Related CVEs: CVE-2017-18342 CVE-2020-1747 Upstream summary: Riccardo Schirone (https://github.com/ret2libc) reports: In FullLoader python/object/new constructor, implemented by construct_python_object_apply, has support for setting […]

Read more
FreeBSD 14 — libsndfile — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — libsndfile — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libsndfile_project — Integer overflow in dataend calculation Related CVEs: CVE-2009-0186 CVE-2009-1788 CVE-2009-1791 CVE-2011-2696 CVE-2017-12562 CVE-2017-14245 CVE-2017-14246 CVE-2017-14634  +12 more Upstream summary: [email protected] reports: Multiple signed integers overflow in function au_read_header […]

Read more
FreeBSD 13 — dino — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — dino — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 February 2024 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dino — Insufficient message sender validation in Dino Related CVEs: CVE-2021-33896 CVE-2023-28686 Upstream summary: Dino team reports: Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to […]

Read more
FreeBSD 14 — libtremor — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — libtremor — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mozilla — multiple vulnerabilities Related CVEs: CVE-2008-1418 CVE-2008-1419 CVE-2008-1420 CVE-2008-1423 CVE-2008-2009 CVE-2012-0444 CVE-2018-5146 CVE-2018-5147 Upstream summary: The Mozilla Foundation reports: CVE-2018-5146: Out of bounds memory write in libvorbis An out […]

Read more
FreeBSD 14 — py36-requests — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py36-requests — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: www/py-requests — Information disclosure vulnerability Upstream summary: The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which […]

Read more
FreeBSD 14 — sieve-connect — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — sieve-connect — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sieve-connect — TLS hostname verification was not occurring Upstream summary: sieve-connect developer Phil Pennock reports: sieve-connect was not actually verifying TLS certificate identities matched the expected hostname. Table of contents […]

Read more
CHAT