FreeBSD

FreeBSD 13 — ja-ppxp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ja-ppxp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ppxp — local root exploit Related CVEs: CVE-2005-0392 Upstream summary: A Debian Advisory reports: Jens Steube discovered that ppxp, yet another PPP program, does not release root privileges when opening […]

Read more
FreeBSD 13 — ja-w3m — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ja-w3m — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: w3m – multiple vulnerabilities Related CVEs: CVE-2006-6772 CVE-2016-9422 CVE-2016-9423 CVE-2016-9424 CVE-2016-9425 CVE-2016-9426 CVE-2016-9428 CVE-2016-9429  +12 more Upstream summary: Tatsuya Kinoshita reports: CVE-2018-6196 * table.c: Prevent negative indent value in feed_table_block_tag(). […]

Read more
FreeBSD 13 — py38-psutil — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py38-psutil — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-psutil — double free vulnerability Related CVEs: CVE-2019-18874 Upstream summary: ret2libc reports: psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a […]

Read more
FreeBSD 13 — proxychains-ng — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — proxychains-ng — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: proxychains-ng — current path as the first directory for the library search path Related CVEs: CVE-2015-3887 Upstream summary: Mamoru TASAKA reports: proxychains4 sets LD_PRELOAD to dlopen libproxychains4.so and execvp() the […]

Read more
FreeBSD 13 — tk — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — tk — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tcl/tk — buffer overflow in ReadImage function Related CVEs: CVE-2007-5137 Upstream summary: A Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl/Tk, allows remote attackers to execute arbitrary code […]

Read more
FreeBSD 13 — isc-dhcp3-client — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — isc-dhcp3-client — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: isc-dhcpd — format string vulnerabilities Related CVEs: CVE-2004-1006 Upstream summary: The ISC DHCP programs are vulnerable to several format string vulnerabilities which may allow a remote attacker to execute arbitrary […]

Read more
FreeBSD 13 — fractorama — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — fractorama — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 19 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tiff — buffer overflow vulnerability Related CVEs: CVE-2004-0803 CVE-2004-0804 CVE-2004-0886 CVE-2004-1308 CVE-2005-1544 Upstream summary: A Gentoo Linux Security Advisory reports: Tavis Ormandy of the Gentoo Linux Security Audit Team discovered […]

Read more
FreeBSD 13 — bind97-base — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — bind97-base — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dns/bind9* — crash on deliberately constructed combination of records Related CVEs: CVE-2012-5166 Upstream summary: ISC reports: A deliberately constructed combination of records could cause named to hang while populating the […]

Read more
FreeBSD 13 — py34-django — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py34-django — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Django — password hash disclosure Related CVEs: CVE-2014-0472 CVE-2014-0473 CVE-2014-0474 CVE-2014-0480 CVE-2014-0481 CVE-2014-0482 CVE-2014-0483 CVE-2015-0219  +12 more Upstream summary: Django release notes: CVE-2018-16984: Password hash disclosure to "view only" admin […]

Read more
FreeBSD 12 — pglogical — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — pglogical — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 January 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pglogical — shell command injection in pglogical.create_subscription() Related CVEs: CVE-2021-3515 Upstream summary: 2ndQuadrant reports: Fix pg_dump/pg_restore execution (CVE-2021-3515) Correctly escape the connection string for both pg_dump and pg_restore so that […]

Read more
CHAT