FreeBSD

FreeBSD 13 — open-motif — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — open-motif — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xpm — image decoding vulnerabilities Related CVEs: CVE-2004-0687 CVE-2004-0688 Upstream summary: Chris Evans discovered several vulnerabilities in the libXpm image decoder: A stack-based buffer overflow in xpmParseColors An integer overflow […]

Read more
FreeBSD 13 — php70-bcmath — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — php70-bcmath — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2016-3074 Upstream summary: The PHP Group reports: BCMath: Fixed bug #72093 (bcpowmod accepts negative scale and corrupts _one_ definition). Exif: Fixed bug #72094 (Out […]

Read more
FreeBSD 13 — transmission-daemon — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — transmission-daemon — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: transmission-daemon — vulnerable to dns rebinding attacks Upstream summary: Google Project Zero reports: The transmission bittorrent client uses a client/server architecture, the user interface is the client which communicates to […]

Read more
FreeBSD 13 — wu-ftpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — wu-ftpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wu-ftpd — remote globbing DoS vulnerability Related CVEs: CVE-2004-0148 CVE-2005-0256 Upstream summary: An iDEFENSE Security Advisory reports: Remote exploitation of an input validation vulnerability in version 2.6.2 of WU-FPTD could […]

Read more
FreeBSD 13 — zhcon — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — zhcon — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zhcon — unauthorized file access Related CVEs: CVE-2005-0072 Upstream summary: Martin Joey Schulze reports: Erik Sjöund discovered that zhcon, a fast console CJK system using the Linux framebuffer, accesses a […]

Read more
FreeBSD 13 — puppet — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — puppet — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: puppet — Silent Configuration Failure Related CVEs: CVE-2012-1906 CVE-2012-1986 CVE-2012-1987 CVE-2012-1988 CVE-2012-1989 CVE-2012-3864 CVE-2012-3865 CVE-2012-3866  +12 more Upstream summary: Puppet reports: A flaw was discovered in Puppet Agent where the […]

Read more
FreeBSD 13 — ja-tdiary — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ja-tdiary — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tdiary — injection vulnerability Related CVEs: CVE-2006-6174 Upstream summary: An undisclosed eRuby injection vulnerability had been discovered in tDiary. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 13 — shutter — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — shutter — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: shutter — arbitrary code execution Related CVEs: CVE-2015-0854 Upstream summary: Luke Farone reports: In the "Shutter" screenshot application, I discovered that using the "Show in folder" menu option while viewing […]

Read more
FreeBSD 13 — mc — multiple vulnerabilities (12 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mc — multiple vulnerabilities (12 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mc — multiple vulnerabilities Related CVEs: CVE-2003-1023 CVE-2004-0226 CVE-2004-0231 CVE-2004-0232 CVE-2004-0494 CVE-2004-1004 CVE-2004-1005 CVE-2004-1009  +4 more Upstream summary: Andrew V. Samoilov reported several vulnerabilities that were corrected in MidnightCommand 4.6.0: […]

Read more
FreeBSD 13 — openzfs-kmod — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — openzfs-kmod — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 April 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sysutils/openzfs-kmod — critical permissions issues Upstream summary: Andrew Walker reports: Issue 1: Users are always granted permissions to cd into a directory. The check for whether execute is present on […]

Read more
CHAT