FreeBSD

FreeBSD 12 — py311-tflite — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py311-tflite — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 January 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-tflite — buffer overflow vulnerability Related CVEs: CVE-2021-37689 CVE-2022-41894 Upstream summary: Thibaut Goetghebuer-Planchon reports: The reference kernel of the CONV_3D_TRANSPOSE TensorFlow Lite operator wrongly increments the data_ptr when adding the […]

Read more
FreeBSD 12 — rubygem-rdoc — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rubygem-rdoc — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 28 January 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: RDoc — command injection vulnerability Related CVEs: CVE-2012-6708 CVE-2015-9251 CVE-2021-31799 Upstream summary: Alexandr Savca reports: RDoc used to call Kernel#open to open a local file. If a Ruby project has […]

Read more
FreeBSD 13 — hsftp — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — hsftp — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: hsftp format string vulnerabilities Upstream summary: Ulf Härnhammar discovered a format string bug in hsftp's file listing code may allow a malicious server to cause arbitrary code execution by the […]

Read more
FreeBSD 13 — serendipity — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — serendipity — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: serendipity — XSS Related CVEs: CVE-2008-1385 CVE-2008-1386 CVE-2019-11870 Upstream summary: MITRE: Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Preview feature or the […]

Read more
FreeBSD 13 — pure-ftpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — pure-ftpd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pureftpd — multiple vulnerabilities Related CVEs: CVE-2011-0418 CVE-2011-1575 Upstream summary: Pure-FTPd development team reports: Support for braces expansion in directory listings has been disabled — Cf. CVE-2011-0418. Fix a STARTTLS […]

Read more
FreeBSD 13 — vinyl — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — vinyl — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Vinyl/Varnish — HTTP/2 parsing deficiency Upstream summary: Vinyl Development Team reports: A deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which […]

Read more
FreeBSD 13 — cinny — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — cinny — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Matrix clients — mxc uri validation in js sdk Related CVEs: CVE-2021-40823 CVE-2021-40824 CVE-2022-36059 CVE-2022-36060 CVE-2022-39236 CVE-2022-39249 CVE-2022-39250 CVE-2022-39251  +3 more Upstream summary: matrix-js-sdk upstream reports: matrix-js-sdk before 34.11.0 is […]

Read more
FreeBSD 13 — linux-f10-tiff — multiple vulnerabilities (18 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-f10-tiff — multiple vulnerabilities (18 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tiff — multiple vulnerabilities Related CVEs: CVE-2009-2347 CVE-2015-8665 CVE-2015-8683 CVE-2016-5314 CVE-2016-5320 CVE-2016-5875 CVE-2017-5225 CVE-2017-7592  +10 more Upstream summary: NVD reports: Please reference CVE/URL list for details Table of contents Symptom […]

Read more
FreeBSD 13 — apache-openoffice-devel — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — apache-openoffice-devel — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 27 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Apache OpenOffice — master password vulnerabilities Related CVEs: CVE-2014-3575 CVE-2015-1774 CVE-2015-4551 CVE-2015-5212 CVE-2015-5213 CVE-2015-5214 CVE-2016-1513 CVE-2017-12607  +11 more Upstream summary: The Apache Openoffice project reports: Apache OpenOffice supports the storage […]

Read more
CHAT