FreeBSD

FreeBSD 13 — id3lib — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — id3lib — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: id3lib — insecure temporary file creation Related CVEs: CVE-2007-4460 Upstream summary: Debian Bug report log reports: When tagging file $foo, a temporary copy of the file is created, and for […]

Read more
FreeBSD 12 — rubygem-carrierwave — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rubygem-carrierwave — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 January 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Carrierwave — Multiple vulnerabilities Related CVEs: CVE-2021-21288 CVE-2021-21305 Upstream summary: Community reports: Fix Code Injection vulnerability in CarrierWave::RMagick Fix SSRF vulnerability in the remote file download feature Table of contents […]

Read more
FreeBSD 13 — jakarta-tomcat — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — jakarta-tomcat — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tomcat — XSS vulnerability in sample applications Related CVEs: CVE-2005-2090 CVE-2007-0450 CVE-2007-1355 CVE-2007-1358 Upstream summary: The Apache Project reports: The JSP and Servlet included in the sample application within the […]

Read more
FreeBSD 13 — ledger — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ledger — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ledger — multiple vulnerabilities Related CVEs: CVE-2017-2807 CVE-2017-2808 Upstream summary: Talos reports: An exploitable buffer overflow vulnerability exists in the tag parsing functionality of Ledger-CLI 3.1.1. A specially crafted journal […]

Read more
FreeBSD 13 — koffice — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — koffice — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 16 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Calligra, KOffice — input validation failure Related CVEs: CAN-2005-2972 CVE-2004-0888 CVE-2004-0889 CVE-2004-1125 CVE-2005-0064 CVE-2007-4352 CVE-2007-5392 CVE-2007-5393  +2 more Upstream summary: KDE Security Advisory reports: A flaw has been found which […]

Read more
FreeBSD 13 — rubygem18-dragonfly — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem18-dragonfly — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-dragonfly — arbitrary code execution Related CVEs: CVE-2013-1756 Upstream summary: Mark Evans reports: Unfortnately there is a security vulnerability in Dragonfly when used with Rails which would potentially allow an […]

Read more
FreeBSD 12 — nextcloud-calendar — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — nextcloud-calendar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 January 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Nextcloud Calendar — SMTP Command Injection Related CVEs: CVE-2022-24838 Upstream summary: reports: SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the […]

Read more
FreeBSD 13 — py311-pymatgen — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py311-pymatgen — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-pymatgen — regular expression denial of service Related CVEs: CVE-2022-42964 Upstream summary: An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an […]

Read more
FreeBSD 13 — ja-trac — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ja-trac — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: trac — potential DOS vulnerability Related CVEs: CVE-2005-3980 CVE-2005-4065 CVE-2005-4305 Upstream summary: Trac development team reports: 0.11.2 is a new stable maintenance release. It contains several security fixes and everyone […]

Read more
FreeBSD 13 — socat — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — socat — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: socat — diffie hellman parameter was not prime Related CVEs: CVE-2012-0219 CVE-2013-3571 CVE-2014-0019 Upstream summary: socat reports: In the OpenSSL address implementation the hard coded 1024 bit DH p parameter […]

Read more
CHAT