FreeBSD

FreeBSD 14 — png — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — png — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 November 2023 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: png — CWE-122: Heap-based Buffer Overflow Related CVEs: CVE-2004-0421 CVE-2004-0597 CVE-2004-0598 CVE-2004-0599 CVE-2007-2445 CVE-2007-5266 CVE-2007-5267 CVE-2007-5268  +12 more Upstream summary: https://github.com/pnggroup/libpng/security/advisories/GHSA-g8hp-mq4h-rqm3 reports: LIBPNG is a reference library for use in […]

Read more
FreeBSD 14 — py39-httpx — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py39-httpx — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 November 2023 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-httpx — input validation vulnerability Related CVEs: CVE-2021-41945 Upstream summary: lebr0nli reports: Encode OSS httpx <=1.0.0.beta0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`. […]

Read more
FreeBSD 14 — linux-c7-openssl-libs — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — linux-c7-openssl-libs — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 November 2023 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenSSL — multiple vulnerabilities Related CVEs: CVE-2016-7055 CVE-2016-8610 CVE-2017-3730 CVE-2017-3731 CVE-2017-3732 Upstream summary: The OpenSSL project reports: Truncated packet could crash via OOB read (CVE-2017-3731) Bad (EC)DHE parameters cause a […]

Read more
FreeBSD 14 — py39-twisted — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py39-twisted — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 November 2023 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-twisted — cookie and authorization headers are leaked when following cross-origin redirects Upstream summary: Twisted developers report: Cookie and Authorization headers are leaked when following cross-origin redirects in twited.web.client.RedirectAgent and […]

Read more
FreeBSD 12 — py39-borgbackup — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py39-borgbackup — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 November 2023 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Borg (Backup) — flaw in cryptographic authentication scheme in Borg allowed an attacker to fake archives and indirectly cause backup data loss. Related CVEs: CVE-2023-36811 Upstream summary: Thomas Waldmann reports: […]

Read more
FreeBSD 14 — crispy-doom — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — crispy-doom — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 November 2023 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: chocolate-doom — Arbitrary code execution Related CVEs: CVE-2020-14983 Upstream summary: Michal Dardas from LogicalTrust reports: The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players […]

Read more
FreeBSD 14 — py34-cryptography — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — py34-cryptography — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 November 2023 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-cryptography — tag forgery vulnerability Related CVEs: CVE-2016-9243 CVE-2018-10903 Upstream summary: The Python Cryptographic Authority (PyCA) project reports: finalize_with_tag() allowed tag truncation by default which can allow tag forgery in […]

Read more
FreeBSD 14 — ruby+oniguruma — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — ruby+oniguruma — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 November 2023 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Multiple implementations — DoS via hash algorithm collision Related CVEs: CVE-2006-5467 CVE-2006-6303 CVE-2008-1447 CVE-2008-2726 CVE-2008-3655 CVE-2008-3656 CVE-2008-3905 CVE-2009-1904  +5 more Upstream summary: oCERT reports: A variety of programming languages suffer […]

Read more
FreeBSD 14 — mariadb103-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — mariadb103-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 24 November 2023 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MariaDB — Nullpointer dereference Related CVEs: CVE-2016-9843 CVE-2018-0739 CVE-2018-25032 CVE-2018-2767 CVE-2018-3054 CVE-2018-3056 CVE-2018-3058 CVE-2018-3060  +12 more Upstream summary: The MariaDB project reports: MariaDB Server is vulnerable to Denial of Service. […]

Read more
FreeBSD 14 — bro — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — bro — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 November 2023 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bro — invalid memory access or heap buffer over-read Related CVEs: CVE-2017-12175 Upstream summary: Jon Siwek of Corelight reports: This is a security patch release to address a potential Denial […]

Read more
CHAT