FreeBSD

FreeBSD 13 — libexo — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libexo — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 January 2023 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: XFCE — Allows executing malicious .desktop files pointing to remote code Related CVEs: CVE-2022-32278 Upstream summary: XFCE Project reports: Prevent executing possibly malicious .desktop files from online sources (ftp://, http:// […]

Read more
FreeBSD 13 — nextcloud-calendar — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — nextcloud-calendar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 December 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Nextcloud Calendar — SMTP Command Injection Related CVEs: CVE-2022-24838 Upstream summary: reports: SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the […]

Read more
FreeBSD 13 — py311-Scrapy — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py311-Scrapy — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 December 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-Scrapy — DoS vulnerability Related CVEs: CVE-2017-14158 CVE-2022-0577 Upstream summary: kmike and nramirezuy report: Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files […]

Read more
FreeBSD 12 — py38-treq — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py38-treq — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 December 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-treq — sensitive information leak vulnerability Related CVEs: CVE-2022-23607 Upstream summary: Treq's request methods (`treq.get`, `treq.post`, `HTTPClient.request`, `HTTPClient.get`, etc.) accept cookies as a dictionary. Such cookies are not bound to […]

Read more
FreeBSD 12 — puppetdb — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — puppetdb — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 December 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: puppetdb — Potential SQL injection Related CVEs: CVE-2020-14060 CVE-2020-14061 CVE-2020-14062 CVE-2020-14195 CVE-2020-7943 CVE-2020-9548 CVE-2021-27021 CVE-2022-31197 Upstream summary: Puppet reports: The org.postgresql/postgresql driver has been updated to version 42.4.1 to address […]

Read more
FreeBSD 12 — py39-treq — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py39-treq — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 December 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-treq — sensitive information leak vulnerability Related CVEs: CVE-2022-23607 Upstream summary: Treq's request methods (`treq.get`, `treq.post`, `HTTPClient.request`, `HTTPClient.get`, etc.) accept cookies as a dictionary. Such cookies are not bound to […]

Read more
FreeBSD 13 — py37-slixmpp — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py37-slixmpp — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 December 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-slixmpp — incomplete SSL certificate validation Related CVEs: CVE-2019-1000021 CVE-2022-45197 Upstream summary: Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server […]

Read more
FreeBSD 13 — rust-nightly — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rust-nightly — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 December 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Rust — Race condition enabling symlink following Related CVEs: CVE-2022-21658 Upstream summary: The Rust Security Response WG was notified that the std::fs::remove_dir_all standard library function is vulnerable to a race […]

Read more
FreeBSD 13 — py39-django-photologue — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py39-django-photologue — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 10 December 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-django-photologue — XSS vulnerability Related CVEs: CVE-2022-4526 Upstream summary: domiee13 reports: A vulnerability was found in django-photologue up to 3.15.1 and classified as problematic. Affected by this issue is some […]

Read more
CHAT