FreeBSD

FreeBSD 14 — php55-ftp — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — php55-ftp — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php5 — multiple vulnerabilities Related CVEs: CVE-2015-4643 CVE-2015-4644 Upstream summary: The PHP project reports: DOM and GD: Fixed bug #69719 (Incorrect handling of paths with NULs). FTP: Improved fix for […]

Read more
FreeBSD 14 — shibboleth-sp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — shibboleth-sp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Shibboleth Service Provider — SQL injection vulnerability in ODBC plugin Related CVEs: CVE-2015-2684 Upstream summary: Internet2 reports: The Shibboleth Service Provider includes a storage API usable for a number of […]

Read more
FreeBSD 14 — mod_auth_mellon — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mod_auth_mellon — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mod_auth_mellon — Redirect URL validation bypass Related CVEs: CVE-2019-13038 Upstream summary: Jakub Hrozek reports: Version 0.17.0 and older of mod_auth_mellon allows the redirect URL validation to be bypassed by specifying […]

Read more
FreeBSD 14 — linux-f10-gnutls — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — linux-f10-gnutls — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gnutls — multiple certificate verification issues Related CVEs: CVE-2014-0092 CVE-2014-1959 Upstream summary: GnuTLS project reports: A vulnerability was discovered that affects the certificate verification functions of all gnutls versions. A […]

Read more
FreeBSD 14 — apache-ant — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — apache-ant — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Apache Ant leaks sensitive information via the java.io.tmpdir Related CVEs: CVE-2020-1945 Upstream summary: Apache reports: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified […]

Read more
FreeBSD 14 — lha — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — lha — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lha — numerous vulnerabilities when extracting archives Related CVEs: CVE-2004-0234 CVE-2004-0235 CVE-2004-0694 CVE-2004-0745 CVE-2004-0769 CVE-2004-0771 Upstream summary: Source code reviews of lha by Lukasz Wojtow, Thomas Biege, and others uncovered […]

Read more
FreeBSD 14 — ja-xlockmore — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ja-xlockmore — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xlockmore — local exploit Related CVEs: CVE-2012-4524 Upstream summary: Ignatios Souvatzis of NetBSD reports: Due to an error in the dclock screensaver in xlockmore, users who explicitly use this screensaver […]

Read more
FreeBSD 14 — getmail — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — getmail — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: getmail — symlink vulnerability during maildir delivery Related CVEs: CVE-2004-0881 Upstream summary: David Watson reports a symlink vulnerability in getmail. If run as root (not the recommended mode of operation), […]

Read more
FreeBSD 14 — mailman — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mailman — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mailman < 2.1.38 — CSRF vulnerability of list mod or member against list admin page Related CVEs: CVE-2003-0038 CVE-2003-0965 CVE-2003-0991 CVE-2003-0992 CVE-2004-0412 CVE-2004-1143 CVE-2005-0202 CVE-2006-1712  +12 more Upstream summary: Mark […]

Read more
FreeBSD 14 — postgresql94-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — postgresql94-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 February 2024 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgresSQL — TYPE in pg_temp execute arbitrary SQL during `SECURITY DEFINER` execution Related CVEs: CVE-2014-8161 CVE-2015-0241 CVE-2015-0242 CVE-2015-0243 CVE-2015-0244 CVE-2015-3165 CVE-2015-3166 CVE-2015-3167  +12 more Upstream summary: The PostgreSQL project reports: […]

Read more
CHAT