FreeBSD

FreeBSD 13 — privoxy — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — privoxy — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: privoxy — multiple vulnerabilities Related CVEs: CVE-2013-2503 CVE-2015-1030 CVE-2015-1031 CVE-2015-1201 CVE-2015-1380 CVE-2015-1381 CVE-2015-1382 CVE-2016-1982  +1 more Upstream summary: Privoxy Developers reports: Prevent invalid reads in case of corrupt chunk-encoded content. […]

Read more
FreeBSD 13 — yii — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — yii — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: yii — Remote arbitrary PHP code execution Related CVEs: CVE-2014-4672 Upstream summary: Yii PHP Framework developers report: We are releasing Yii 1.1.15 to fix a security issue found in 1.1.14. […]

Read more
FreeBSD 13 — lives — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — lives — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lives — insecure files permissions Upstream summary: Debian reports: smogrify script creates insecure temporary files. lives creates and uses world-writable directory. Table of contents Symptom & Impact Environment & Reproduction […]

Read more
FreeBSD 13 — cs-openoffice — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — cs-openoffice — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openoffice — DOC document heap overflow vulnerability Related CVEs: CVE-2004-0752 CVE-2005-0941 Upstream summary: AD-LAB reports that a heap-based buffer overflow vulnerability exists in OpenOffice's handling of DOC documents. When reading […]

Read more
FreeBSD 13 — mnemo — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mnemo — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mnemo — Cross site scripting vulnerabilities in several of the notepad name and note data fields Upstream summary: Announce of Mnemo H3 (2.0.3) (final): This [2.0.3] is a security release […]

Read more
FreeBSD 13 — rubygem-actionview — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem-actionview — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 7 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Rails — XSS vulnerabilities Related CVEs: CVE-2015-7576 CVE-2015-7577 CVE-2015-7581 CVE-2016-0751 CVE-2016-0752 CVE-2016-0753 CVE-2016-2097 CVE-2016-2098  +12 more Upstream summary: Ruby on Rails blog: This is an announcement to let you know […]

Read more
FreeBSD 13 — py38-twisted — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py38-twisted — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-twisted — cookie and authorization headers are leaked when following cross-origin redirects Related CVEs: CVE-2019-12387 CVE-2019-9512 CVE-2019-9514 CVE-2019-9515 CVE-2020-10108 CVE-2020-10109 Upstream summary: Twisted developers report: Cookie and Authorization headers are […]

Read more
FreeBSD 13 — fontconfig — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — fontconfig — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fontconfig — insufficiently cache file validation Related CVEs: CVE-2016-5384 Upstream summary: Debian security team reports: Tobias Stoeckmann discovered that cache files are insufficiently validated in fontconfig, a generic font configuration […]

Read more
FreeBSD 13 — tin — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — tin — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tin — buffer overflow vulnerabilities Upstream summary: Urs Janssen and Aleksey Salow report possible buffer overflows in tin versions 1.8.0 and 1.8.1. OpenPKG project elaborates there is an allocation off-by-one […]

Read more
FreeBSD 13 — spamdyke — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — spamdyke — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 6 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: spamdyke — Buffer Overflow Vulnerabilities Related CVEs: CVE-2008-2784 CVE-2012-0070 CVE-2012-0802 Upstream summary: Secunia reports: Fixed a number of very serious errors in the usage of snprintf()/vsnprintf(). The return value was […]

Read more
CHAT