FreeBSD

FreeBSD 13 — cgiwrap — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — cgiwrap — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: cgiwrap — XSS Vulnerability Related CVEs: CVE-2008-2852 Upstream summary: Secunia reports: A vulnerability has been reported in CGIWrap, which can be exploited by malicious people to conduct cross-site scripting attacks. […]

Read more
FreeBSD 13 — weex — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — weex — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: weex — remote format string vulnerability Upstream summary: Emanuel Haupt reports: Someone who controls an FTP server that weex will log in to can set up malicious data in the […]

Read more
FreeBSD 13 — portupgrade — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — portupgrade — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: portupgrade — insecure temporary file handling vulnerability Related CVEs: CVE-2005-0610 Upstream summary: Simon L. Nielsen discovered that portupgrade handles temporary files in an insecure manner. This could allow an unprivileged […]

Read more
FreeBSD 13 — py37-suds — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py37-suds — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-suds — vulnerable to symlink attacks Related CVEs: CVE-2013-2217 Upstream summary: SUSE reports: cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries […]

Read more
FreeBSD 13 — py36-pillow — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py36-pillow — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Pillow — Multiple vulnerabilities Related CVEs: CVE-2019-16865 CVE-2019-19911 CVE-2020-5310 CVE-2020-5311 CVE-2020-5312 CVE-2020-5313 Upstream summary: Pillow developers report: This release addresses several security problems, as well as addressing CVE-2019-19911. CVE-2019-19911 is […]

Read more
FreeBSD 13 — quassel-core — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — quassel-core — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: quassel — multiple vulnerabilities Upstream summary: Gentoo reports: quasselcore: corruption of heap metadata caused by qdatastream leading to preauth remote code execution. Severity: high, by default the server port is […]

Read more
FreeBSD 13 — xzgv — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — xzgv — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zgv, xzgv — heap overflow vulnerability Related CVEs: CVE-2004-0994 CVE-2006-1060 Upstream summary: Gentoo reports: Andrea Barisani of Gentoo Linux discovered xzgv and zgv allocate insufficient memory when rendering images with […]

Read more
FreeBSD 13 — ipython — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ipython — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: devel/ipython — multiple vulnerabilities Related CVEs: CVE-2015-4706 CVE-2015-4707 CVE-2015-5607 CVE-2015-6938 CVE-2015-7337 Upstream summary: Matthias Bussonnier reports: Summary: Local folder name was used in HTML templates without escaping, allowing XSS in […]

Read more
FreeBSD 13 — nextcloud — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — nextcloud — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Nextcloud — Password share by mail not hashed Related CVEs: CVE-2020-8183 Upstream summary: The Nextcloud project reports: NC-SA-2020-026 (low): Password of share by mail is not hashed when given on […]

Read more
FreeBSD 13 — xerces-c — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — xerces-c — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 26 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: shibboleth-sp — vulnerable to forged user attribute data Related CVEs: CVE-2016-0729 CVE-2016-2099 CVE-2016-4463 CVE-2018-0486 CVE-2018-0489 Upstream summary: Shibboleth consortium reports: Shibboleth SP software vulnerable to additional data forgery flaws The […]

Read more
CHAT