FreeBSD

FreeBSD 13 — libbrotli — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libbrotli — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: brotli — buffer overflow Related CVEs: CVE-2016-1624 CVE-2016-1968 Upstream summary: Google Chrome Releases reports: [583607] High CVE-2016-1624: Buffer overflow in Brotli. Credit to lukezli. Mozilla Foundation reports: Security researcher Luke […]

Read more
FreeBSD 13 — linux-c7-openssl-libs — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-c7-openssl-libs — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenSSL — multiple vulnerabilities Related CVEs: CVE-2016-7055 CVE-2016-8610 CVE-2017-3730 CVE-2017-3731 CVE-2017-3732 Upstream summary: The OpenSSL project reports: Truncated packet could crash via OOB read (CVE-2017-3731) Bad (EC)DHE parameters cause a […]

Read more
FreeBSD 13 — rubygem19-dragonfly — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem19-dragonfly — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-dragonfly — arbitrary code execution Related CVEs: CVE-2013-1756 Upstream summary: Mark Evans reports: Unfortnately there is a security vulnerability in Dragonfly when used with Rails which would potentially allow an […]

Read more
FreeBSD 13 — gstreamer-plugins-good — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — gstreamer-plugins-good — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gstreamer-plugins-good — multiple memory overflows Related CVEs: CVE-2009-0386 CVE-2009-0387 CVE-2009-0397 Upstream summary: Secunia reports: Tobias Klein has reported some vulnerabilities in GStreamer Good Plug-ins, which can potentially be exploited by […]

Read more
FreeBSD 13 — libXinerama — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libXinerama — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xorg — protocol handling issues in X Window System client libraries Related CVEs: CVE-2013-1981 CVE-2013-1982 CVE-2013-1983 CVE-2013-1984 CVE-2013-1985 CVE-2013-1986 CVE-2013-1987 CVE-2013-1988  +12 more Upstream summary: freedesktop.org reports: Ilja van Sprundel, […]

Read more
FreeBSD 13 — rubygem-rails — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem-rails — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rails — multiple vulnerabilities Related CVEs: CVE-2007-3227 CVE-2007-6077 CVE-2008-4094 CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 CVE-2012-5664 CVE-2013-0155  +12 more Upstream summary: Ruby on Rails blog: Rails 4.2.5.2, 4.1.14.2, and 3.2.22.2 have been released! […]

Read more
FreeBSD 13 — py311-beaker — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py311-beaker — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-beaker — arbitrary code execution vulnerability Related CVEs: CVE-2013-7489 Upstream summary: matheusbrat reports: The Beaker library through 1.12.1 for Python is affected by deserialization of untrusted data, which could lead […]

Read more
FreeBSD 12 — py38-salt — multiple vulnerabilities (16 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py38-salt — multiple vulnerabilities (16 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 January 2022 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: salt — multiple vulnerabilities Related CVEs: CVE-2019-17361 CVE-2020-11651 CVE-2020-11652 CVE-2020-16846 CVE-2020-17490 CVE-2020-25592 CVE-2020-28243 CVE-2020-28972  +8 more Upstream summary: SaltStack reports multiple security vulnerabilities in Salt CVE-2021-3197: The Salt-API.s SSH client […]

Read more
FreeBSD 13 — wemux — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — wemux — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wemux — read-only can be bypassed Upstream summary: JonApps reports: The read-only mode can be bypassed and any command sent to bash session Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 13 — extman — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — extman — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 January 2022 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: extman — password bypass vulnerability Upstream summary: Extmail team reports: Emergency update #4 fixes a serious security vulnerability. Successful exploit of this vulnerability would allow attacker to change user's password […]

Read more
CHAT