FreeBSD

FreeBSD 13 — pwlib — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — pwlib — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Vulnerabilities in H.323 implementations Related CVEs: CVE-2004-0097 Upstream summary: The NISCC and the OUSPG developed a test suite for the H.323 protocol. This test suite has uncovered vulnerabilities in several […]

Read more
FreeBSD 13 — libvorbis — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libvorbis — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libvorbis — two vulnerabilities Related CVEs: CVE-2007-3106 CVE-2008-1419 CVE-2008-1420 CVE-2008-1423 CVE-2009-3379 CVE-2017-14160 CVE-2017-14632 CVE-2017-14633  +3 more Upstream summary: Two vulnerabilities were fixed in the upstream repository: The bark_noise_hybridmp function allows […]

Read more
FreeBSD 13 — file — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — file — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: file — Heap buffer overflow possible Related CVEs: CVE-2007-1536 CVE-2014-1943 CVE-2014-2270 CVE-2014-3710 CVE-2014-8116 CVE-2014-8117 Upstream summary: mitre reports cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number […]

Read more
FreeBSD 13 — libsoup — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libsoup — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libsoup — stack based buffer overflow Related CVEs: CVE-2011-2054 CVE-2017-2885 Upstream summary: Tobias Mueller reports: libsoup is susceptible to a stack based buffer overflow attack when using chunked encoding. Regardless […]

Read more
FreeBSD 13 — swfdec — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — swfdec — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: swfdec — exposure of sensitive information Related CVEs: CVE-2008-1834 Upstream summary: Secunia reports: A vulnerability has been reported in swfdec, which can be exploited by malicious people to disclose sensitive […]

Read more
FreeBSD 13 — smbftpd — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — smbftpd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: smbftpd — format string vulnerability Related CVEs: CVE-2007-5184 Upstream summary: Secunia reports: Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute arbitrary […]

Read more
FreeBSD 13 — vtiger — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — vtiger — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: vtiger — multiple remote file inclusion vulnerabilities Related CVEs: CVE-2006-5289 Upstream summary: Dedi Dwianto a.k.a the_day reports: Input passed to the "$calpath" parameter in update.php is not properly verified before […]

Read more
FreeBSD 12 — py310-fail2ban — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py310-fail2ban — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 June 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fail2ban — possible RCE vulnerability in mailing action using mailutils Related CVEs: CVE-2021-32749 Upstream summary: Jakub Żoczek reports: Command mail from mailutils package used in mail actions like mail-whois can […]

Read more
FreeBSD 13 — linux-f10-openssl — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-f10-openssl — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenSSL — multiple vulnerabilities Related CVEs: CVE-2009-1377 CVE-2009-1378 CVE-2011-3207 CVE-2011-3210 Upstream summary: OpenSSL Team reports: Two security flaws have been fixed in OpenSSL 1.0.0e Under certain circumstances OpenSSL's internal certificate […]

Read more
FreeBSD 13 — libetpan — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libetpan — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 June 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libetpan — null dereference vulnerability in MIME parsing component Related CVEs: CVE-2017-8825 Upstream summary: rwhitworth reports: I was using American Fuzzy Lop (afl-fuzz) to fuzz input to the mime-parse test […]

Read more
CHAT