FreeBSD

FreeBSD 13 — py27-yaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py27-yaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-yaml — FullLoader (still) exploitable for arbitrary command execution Related CVEs: CVE-2017-18342 CVE-2020-1747 Upstream summary: Riccardo Schirone (https://github.com/ret2libc) reports: In FullLoader python/object/new constructor, implemented by construct_python_object_apply, has support for setting […]

Read more
FreeBSD 13 — dircproxy — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — dircproxy — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dircproxy — remote denial of service Related CVEs: CVE-2007-5226 Upstream summary: Securiweb reports: dircproxy allows remote attackers to cause a denial of service (segmentation fault) via an ACTION command without […]

Read more
FreeBSD 13 — openssl-beta-overwrite-base — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — openssl-beta-overwrite-base — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openssl — potential SSL 2.0 rollback Related CVEs: CVE-2005-2969 Upstream summary: Vulnerability: Such applications are affected if they use the option SSL_OP_MSIE_SSLV2_RSA_PADDING. This option is implied by use of SSL_OP_ALL, […]

Read more
FreeBSD 13 — ruby20-gems — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ruby20-gems — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygems — request hijacking vulnerability Related CVEs: CVE-2013-4287 CVE-2013-4363 CVE-2015-3900 Upstream summary: Jonathan Claudius reports: RubyGems provides the ability of a domain to direct clients to a separate host that […]

Read more
FreeBSD 13 — xdelta — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — xdelta — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xdelta3 — buffer overflow vulnerability Related CVEs: CVE-2014-9765 Upstream summary: Stepan Golosunov reports: Buffer overflow was found and fixed in xdelta3 binary diff tool that allows arbitrary code execution from […]

Read more
FreeBSD 12 — py310-cinder — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py310-cinder — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 February 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-cinder — unauthorized data access Related CVEs: CVE-2014-3641 CVE-2022-47951 Upstream summary: Utkarsh Gupta reports: An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before […]

Read more
FreeBSD 13 — mercurial — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mercurial — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mercurial — multiple issues Related CVEs: CVE-2016-3068 CVE-2016-3069 CVE-2016-3105 CVE-2016-3630 CVE-2017-1000115 CVE-2017-1000116 Upstream summary: mercurial developers reports: Mercurial prior to version 4.3 is vulnerable to a missing symlink check that […]

Read more
FreeBSD 13 — linux-f10-libgcrypt — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-f10-libgcrypt — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: GnuPG and Libgcrypt — side-channel attack vulnerability Related CVEs: CVE-2013-4242 Upstream summary: Werner Koch of the GNU project reports: Noteworthy changes in version 1.5.3: Mitigate the Yarom/Falkner flush+reload side-channel attack […]

Read more
FreeBSD 13 — silc-server — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — silc-server — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: silc — pkcs_decode buffer overflow Upstream summary: Core Security Technologies reports: A remote buffer overflow vulnerability found in a library used by both the SILC server and client to process […]

Read more
FreeBSD 13 — fwbuilder — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — fwbuilder — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 February 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fwbuilder — security issue in temporary file handling Related CVEs: CVE-2009-4664 Upstream summary: Firewall Builder release notes reports: Vadim Kurland ([email protected]) reports: Fwbuilder and libfwbuilder 3.0.4 through to 3.0.6 generate […]

Read more
CHAT