FreeBSD

FreeBSD 13 — unzip — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — unzip — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: unzip — multiple vulnerabilities Related CVEs: CVE-2005-2475 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2014-9636 CVE-2015-1315 CVE-2015-7696 CVE-2015-7697 Upstream summary: Gustavo Grieco reports: Two issues were found in unzip 6.0: * A heap overflow […]

Read more
FreeBSD 13 — typo3-9-php — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — typo3-9-php — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 14 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: typo3 — multiple vulnerabilities Related CVEs: CVE-2019-10912 CVE-2019-12747 CVE-2019-12748 CVE-2020-11063 CVE-2020-11064 CVE-2020-11065 CVE-2020-11066 CVE-2020-11067  +3 more Upstream summary: Typo3 Team reports: In case an attacker manages to generate a valid […]

Read more
FreeBSD 13 — sogo — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — sogo — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: SOGo — SAML user authentication impersonation Related CVEs: CVE-2021-33054 Upstream summary: sogo.nu reports: SOGo was not validating the signatures of any SAML assertions it received. This means any actor with […]

Read more
FreeBSD 13 — py310-Flask-Cors — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py310-Flask-Cors — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-Flask-Cors — directory traversal vulnerability Related CVEs: CVE-2020-25032 Upstream summary: praetorian-colby-morgan reports: An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal […]

Read more
FreeBSD 13 — ru-wordpress-ru_RU — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ru-wordpress-ru_RU — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: wordpress — XSS Upstream summary: The WordPress team reports: A cross-site scripting (XSS) vulnerability affecting the Avatar block type Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 13 — sql-ledger — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — sql-ledger — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sql-ledger — security bypass vulnerability Related CVEs: CVE-2006-4244 CVE-2006-4731 CVE-2006-5872 Upstream summary: Chris Travers reports: George Theall of Tenable Security notified the LedgerSMB core team today of an authentication bypass […]

Read more
FreeBSD 12 — libmysofa — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libmysofa — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 December 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libmysoft — Heap-based buffer overflow vulnerability Related CVEs: CVE-2021-3756 Upstream summary: Zhengjie Du reports: There are some heap-buffer-overflows in mysofa2json of libmysofa. They are in function loudness, mysofa_check and readOHDRHeaderMessageDataLayout. […]

Read more
FreeBSD 13 — py310-kerberos — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py310-kerberos — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-kerberos — DoS and MitM vulnerabilities Related CVEs: CVE-2015-3206 Upstream summary: macosforgebot reports: The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows […]

Read more
FreeBSD 13 — gsoap — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — gsoap — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gsoap — remote code execution via via overflow Related CVEs: CVE-2017-9765 Upstream summary: Senrio reports: Genivia gSOAP is prone to a stack-based buffer-overflow vulnerability because it fails to properly bounds […]

Read more
FreeBSD 13 — timidity++-gtk — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — timidity++-gtk — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: TiMidity++ — Multiple vulnerabilities Related CVEs: CVE-2017-11546 CVE-2017-11547 CVE-2017-11549 Upstream summary: qflb.wu of DBAPPSecurity reports: Ihe insert_note_steps function in readmidi.c in TiMidity++ 2.14.0 can cause a denial of service(divide-by-zero error […]

Read more
CHAT