FreeBSD

FreeBSD 12 — cinny — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — cinny — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 July 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Matrix clients — mxc uri validation in js sdk Related CVEs: CVE-2021-40823 CVE-2021-40824 CVE-2022-36059 CVE-2022-36060 CVE-2022-39236 CVE-2022-39249 CVE-2022-39250 CVE-2022-39251  +3 more Upstream summary: matrix-js-sdk upstream reports: matrix-js-sdk before 34.11.0 is […]

Read more
FreeBSD 13 — py310-twisted — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py310-twisted — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-twisted — cookie and authorization headers are leaked when following cross-origin redirects Upstream summary: Twisted developers report: Cookie and Authorization headers are leaked when following cross-origin redirects in twited.web.client.RedirectAgent and […]

Read more
FreeBSD 12 — py39-numpy — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py39-numpy — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 July 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-numpy — Missing return-value validation of the function PyArray_DescrNew Related CVEs: CVE-2021-41495 Upstream summary: Numpy reports: At most call-sites for PyArray_DescrNew, there are no validations of its return, but an […]

Read more
FreeBSD 13 — dovecot — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — dovecot — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 5 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Dovecot — DoS Related CVEs: CVE-2008-4577 CVE-2008-4578 CVE-2009-3897 CVE-2011-1929 CVE-2017-15132 CVE-2017-2669 CVE-2019-10691 CVE-2019-11494  +12 more Upstream summary: Dovecot reports: A DoS is possible with a large number of address headers […]

Read more
FreeBSD 13 — apache+mod_ssl+mod_deflate+ipv — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — apache+mod_ssl+mod_deflate+ipv — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: apache — Prevent chunk-size integer overflow on platforms where sizeof(int) < sizeof(long) Related CVEs: CVE-2005-2088 CVE-2005-3352 CVE-2006-3747 Upstream summary: Apache ChangeLog reports: Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c […]

Read more
FreeBSD 13 — opendkim — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — opendkim — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: DomainKeys Identified Mail (DKIM) Verifiers may inappropriately convey message trust Upstream summary: US-CERT reports: DomainKeys Identified Mail (DKIM) Verifiers may inappropriately convey message trust when messages are signed using test […]

Read more
FreeBSD 13 — opendchub — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — opendchub — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Open DC Hub — remote buffer overflow vulnerability Upstream summary: Donato Ferrante reported an exploitable buffer overflow in this software package. Any user that can login with 'admin' privileges can […]

Read more
FreeBSD 13 — php5-openssl — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — php5-openssl — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 4 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php5 — multiple vulnerabilities Related CVEs: CVE-2015-6831 CVE-2015-6832 CVE-2015-6833 Upstream summary: The PHP project reports: Core: Fixed bug #69793 (Remotely triggerable stack exhaustion via recursive method calls). Fixed bug #70121 […]

Read more
FreeBSD 13 — bidwatcher — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — bidwatcher — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 July 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bidwatcher — format string vulnerability Related CVEs: CVE-2005-0158 Upstream summary: A Debian Security Advisory reports: Ulf Härnhammer from the Debian Security Audit Project discovered a format string vulnerability in bidwatcher, […]

Read more
CHAT