FreeBSD

FreeBSD 13 — h2o-devel — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — h2o-devel — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 February 2023 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: h2o — HTTP/2 Rapid Reset attack vulnerability Related CVEs: CVE-2019-9512 CVE-2019-9514 CVE-2019-9515 CVE-2021-43848 CVE-2023-30847 CVE-2023-44487 Upstream summary: Kazuo Okuhu reports: H2O is vulnerable to the HTTP/2 Rapid Reset attack. An […]

Read more
FreeBSD 13 — librecad — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — librecad — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 February 2023 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: librecad — out-of-bounds read in importshp plugin Related CVEs: CVE-2023-30259 Upstream summary: Albin Eldstål-Ahrens reports: An out-of-bounds read on a heap buffer in the importshp plugin may allow an attacker […]

Read more
FreeBSD 12 — jellyfin — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — jellyfin — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 February 2023 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: jellyfin — Multiple vulnerabilities Related CVEs: CVE-2023-30626 CVE-2023-30627 Upstream summary: [email protected] reports: Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a […]

Read more
FreeBSD 13 — e2fsprogs-nobootfsck — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — e2fsprogs-nobootfsck — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 February 2023 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: e2fsprogs — out-of-bounds read/write vulnerability Related CVEs: CVE-2022-1304 Upstream summary: Nils Bars reports: During the processing of [a specially fuzzed disk image], an out-of-bounds write is triggered and causes a […]

Read more
FreeBSD 12 — krb5-devel — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — krb5-devel — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 18 February 2023 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: krb5 — Double-free in KDC TGS processing Related CVEs: CVE-2017-11368 CVE-2017-11462 CVE-2022-42898 CVE-2023-39975 Upstream summary: The MIT krb5 Team reports: When issuing a ticket for a TGS renew or validate […]

Read more
FreeBSD 13 — py39-OWSLib — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py39-OWSLib — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 February 2023 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py39-OWSLib — arbitrary file read vulnerability Related CVEs: CVE-2023-27476 Upstream summary: Jorge Rosillo reports: OWSLib's XML parser (which supports both `lxml` and `xml.etree`) does not disable entity resolution for `lxml`, […]

Read more
FreeBSD 13 — py38-wagtail — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py38-wagtail — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 February 2023 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-wagtail — stored XSS vulnerability Related CVEs: CVE-2020-11001 CVE-2020-11037 CVE-2020-15118 CVE-2023-28836 CVE-2023-28837 Upstream summary: A stored cross-site scripting (XSS) vulnerability exists on ModelAdmin views within the Wagtail admin interface. A […]

Read more
FreeBSD 12 — open-vm-tools-nox — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — open-vm-tools-nox — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 February 2023 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: open-vm-tools — Multiple vulnerabilities Related CVEs: CVE-2023-34058 CVE-2023-34059 Upstream summary: VMware reports: This update includes 2 security fixes: High CVE-2023-34058: SAML token signature bypass vulnerability High CVE-2023-34059: File descriptor hijack […]

Read more
FreeBSD 12 — e2fsprogs-roothardlinks — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — e2fsprogs-roothardlinks — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 February 2023 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: e2fsprogs — out-of-bounds read/write vulnerability Related CVEs: CVE-2022-1304 Upstream summary: Nils Bars reports: During the processing of [a specially fuzzed disk image], an out-of-bounds write is triggered and causes a […]

Read more
FreeBSD 12 — py37-tflite — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py37-tflite — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 February 2023 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-tflite — buffer overflow vulnerability Related CVEs: CVE-2021-37689 CVE-2022-41894 Upstream summary: Thibaut Goetghebuer-Planchon reports: The reference kernel of the CONV_3D_TRANSPOSE TensorFlow Lite operator wrongly increments the data_ptr when adding the […]

Read more
CHAT