FreeBSD

FreeBSD 13 — p11-kit — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — p11-kit — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p11-kit — Multiple vulnerabilities Related CVEs: CVE-2020-29361 CVE-2020-29362 CVE-2020-29363 Upstream summary: The p11-glue project reports: CVE-2020-29363: Out-of-bounds write in p11_rpc_buffer_get_byte_array_value function A heap-based buffer overflow has been discovered in the […]

Read more
FreeBSD 13 — p5-PathTools — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — p5-PathTools — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p5-PathTools — File::Spec::canonpath loses taint Related CVEs: CVE-2015-8607 Upstream summary: Ricardo Signes reports: Beginning in PathTools 3.47 and/or perl 5.20.0, the File::Spec::canonpath() routine returned untained strings even if passed tainted […]

Read more
FreeBSD 13 — busybox — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — busybox — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: LZO — potential buffer overrun when processing malicious input data Related CVEs: CVE-2014-4608 Upstream summary: Markus Franz Xaver Johannes Oberhumer reports, in the package's NEWS file: Fixed a potential integer […]

Read more
FreeBSD 13 — openjdk7-jre — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — openjdk7-jre — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: java — multiple vulnerabilities Related CVEs: CVE-2015-4734 CVE-2015-4803 CVE-2015-4805 CVE-2015-4806 CVE-2015-4810 CVE-2015-4835 CVE-2015-4840 CVE-2015-4842  +12 more Upstream summary: Oracle reports: This Critical Patch Update contains 25 new security fixes for […]

Read more
FreeBSD 13 — trojita — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — trojita — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mail/trojita — may leak mail contents (not user credentials) over unencrypted connection Related CVEs: CVE-2014-2567 Upstream summary: Jan Kundrát reports: An SSL stripping vulnerability was discovered in Trojitá, a fast […]

Read more
FreeBSD 13 — x11vnc — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — x11vnc — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: x11vnc — access to shared memory segments Related CVEs: CVE-2006-2450 CVE-2020-29074 Upstream summary: [email protected] reports: scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other […]

Read more
FreeBSD 13 — libssh — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libssh — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 17 May 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libssh — possible heap-buffer overflow vulnerability Related CVEs: CVE-2014-0017 CVE-2015-1782 CVE-2015-3146 CVE-2016-0739 CVE-2018-10933 CVE-2019-14889 CVE-2019-3855 CVE-2019-3856  +9 more Upstream summary: libssh security advisories: The SSH protocol keeps track of two […]

Read more
CHAT