FreeBSD

FreeBSD 13 — wayland — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — wayland — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wayland — integer overflow Related CVEs: CVE-2013-2003 Upstream summary: Tobias Stoeckmann reports: The libXcursor fix for CVE-2013-2003 has never been imported into wayland, leaving it vulnerable to it. Table of […]

Read more
FreeBSD 13 — py310-tflite — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py310-tflite — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-tflite — buffer overflow vulnerability Related CVEs: CVE-2021-37689 CVE-2022-41894 Upstream summary: Thibaut Goetghebuer-Planchon reports: The reference kernel of the CONV_3D_TRANSPOSE TensorFlow Lite operator wrongly increments the data_ptr when adding the […]

Read more
FreeBSD 13 — py39-pysaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py39-pysaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pysaml2 — multiple vulnerabilities Related CVEs: CVE-2021-21238 CVE-2021-21239 Upstream summary: pysaml2 Releases: Fix processing of invalid SAML XML documents – CVE-2021-21238 Fix unspecified xmlsec1 key-type preference – CVE-2021-21239 Table of […]

Read more
FreeBSD 13 — heimdal — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — heimdal — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: heimdal — bypass of capath policy Related CVEs: CVE-2004-0371 CVE-2004-0434 CVE-2005-0469 CVE-2005-2040 CVE-2006-0582 CVE-2006-0677 Upstream summary: Viktor Dukhovni reports: Commit f469fc6 (2010-10-02) inadvertently caused the previous hop realm to not […]

Read more
FreeBSD 13 — atril-lite — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — atril-lite — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: evince and atril — command injection vulnerability in CBT handler Related CVEs: CVE-2017-1000083 Upstream summary: GNOME reports: The comic book backend in evince 3.24.0 (and earlier) is vulnerable to a […]

Read more
FreeBSD 13 — automake — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — automake — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: automake — Insecure 'distcheck' recipe granted world-writable distdir Related CVEs: CVE-2012-3386 Upstream summary: GNU reports: The recipe of the 'distcheck' target granted temporary world-write permissions on the extracted distdir. This […]

Read more
FreeBSD 13 — openhab — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — openhab — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openhab — log4j remote code injection Related CVEs: CVE-2021-44228 Upstream summary: Openhab reports: Any openHAB instance that is publicly available or which consumes untrusted content from remote servers is potentially […]

Read more
FreeBSD 13 — osc — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — osc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: osc — shell command injection via crafted _service files Related CVEs: CVE-2015-0778 Upstream summary: SUSE Security Update reports: osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell […]

Read more
FreeBSD 13 — dojo — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — dojo — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dojo — cross-site scripting and other vulnerabilities Upstream summary: The Dojo Toolkit team reports: Some PHP files did not properly escape input. Some files could operate like "open redirects". A […]

Read more
FreeBSD 13 — guile — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — guile — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 October 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: guile2 — multiple vulnerabilities Related CVEs: CVE-2016-8605 CVE-2016-8606 Upstream summary: Ludovic Courtès reports: The REPL server is vulnerable to the HTTP inter-protocol attack The ‘mkdir’ procedure of GNU Guile, an […]

Read more
CHAT