FreeBSD

FreeBSD 13 — bitmessage — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — bitmessage — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 September 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bitmessage — remote code execution vulnerability Upstream summary: Bitmessage developers report: A remote code execution vulnerability has been spotted in use against some users running PyBitmessage v0.6.2. The cause was […]

Read more
FreeBSD 13 — php4-mbstring — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — php4-mbstring — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 September 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php-mbstring — php mbstring buffer overflow vulnerability Related CVEs: CVE-2008-5557 Upstream summary: SecurityFocus reports: PHP is prone to a buffer-overflow vulnerability because it fails to perform boundary checks before copying […]

Read more
FreeBSD 13 — py39-unicorn — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py39-unicorn — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 September 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py39-unicorn — sandbox escape and arbitrary code execution vulnerability Related CVEs: CVE-2021-44078 Upstream summary: jwang-a reports: An issue was discovered in split_region in uc.c in Unicorn Engine before 2.0.0-rc5. It […]

Read more
FreeBSD 13 — sogo-activesync — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — sogo-activesync — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 September 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: SOGo — SAML user authentication impersonation Related CVEs: CVE-2021-33054 Upstream summary: sogo.nu reports: SOGo was not validating the signatures of any SAML assertions it received. This means any actor with […]

Read more
FreeBSD 13 — linux-c6-libsamplerate — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-c6-libsamplerate — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 September 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libsamplerate — multiple vulnerabilities Related CVEs: CVE-2017-7697 Upstream summary: NVD reports: In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file. […]

Read more
FreeBSD 13 — pear-Horde_Image — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — pear-Horde_Image — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 September 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pear-Horde_Image — DoS vulnerability Related CVEs: CVE-2017-9773 CVE-2017-9774 Upstream summary: Michael J Rubinsky reports: The second vulnerability (CVE-2017-9773) is a DOS vulnerability. This only affects Horde installations that do not […]

Read more
FreeBSD 13 — linux-c7-libsndfile — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-c7-libsndfile — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 September 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libsndfile — out-of-bounds reads Related CVEs: CVE-2017-12562 CVE-2017-14245 CVE-2017-14246 CVE-2017-14634 CVE-2017-17456 CVE-2017-17457 CVE-2017-6892 CVE-2017-7585  +7 more Upstream summary: Xin-Jiang on Github reports: CVE-2017-14245 (Medium): An out of bounds read in […]

Read more
FreeBSD 12 — py39-django-photologue — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py39-django-photologue — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 September 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-django-photologue — XSS vulnerability Related CVEs: CVE-2022-4526 Upstream summary: domiee13 reports: A vulnerability was found in django-photologue up to 3.15.1 and classified as problematic. Affected by this issue is some […]

Read more
FreeBSD 13 — lldpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — lldpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 September 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lldpd — Buffer overflow/Denial of service Related CVEs: CVE-2015-8011 CVE-2015-8012 Upstream summary: The lldpd developer Vincent Bernat reports: A buffer overflow may allow arbitrary code execution only if hardening was […]

Read more
FreeBSD 13 — libwmf — multiple vulnerabilities (13 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libwmf — multiple vulnerabilities (13 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 September 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libwmf — multiple vulnerabilities Related CVEs: CVE-2004-0941 CVE-2006-3376 CVE-2007-0455 CVE-2007-2756 CVE-2007-3472 CVE-2007-3473 CVE-2007-3477 CVE-2009-1364  +5 more Upstream summary: Mitre reports: Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 […]

Read more
CHAT