FreeBSD

FreeBSD 13 — py32-djblets — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py32-djblets — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-djblets — Self-XSS vulnerability Upstream summary: Djblets Release Notes reports: A recently-discovered vulnerability in the datagrid templates allows an attacker to generate a URL to any datagrid page containing malicious […]

Read more
FreeBSD 13 — asterisk-bristuff — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — asterisk-bristuff — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: asterisk — remote heap overwrite vulnerability Upstream summary: Adam Boileau of Security-Assessment.com reports: The Asterisk Skinny channel driver for Cisco SCCP phones (chan_skinny.so) incorrectly validates a length value in the […]

Read more
FreeBSD 13 — timidity++-slang — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — timidity++-slang — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: TiMidity++ — Multiple vulnerabilities Related CVEs: CVE-2017-11546 CVE-2017-11547 CVE-2017-11549 Upstream summary: qflb.wu of DBAPPSecurity reports: Ihe insert_note_steps function in readmidi.c in TiMidity++ 2.14.0 can cause a denial of service(divide-by-zero error […]

Read more
FreeBSD 13 — netscape-navigator — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — netscape-navigator — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 7 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libpng stack-based buffer overflow and other code concerns Related CVEs: CVE-2004-0597 CVE-2004-0598 CVE-2004-0599 Upstream summary: Chris Evans has discovered multiple vulnerabilities in libpng, which can be exploited by malicious people […]

Read more
FreeBSD 13 — ezbounce — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ezbounce — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 7 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ezbounce remote format string vulnerability Related CVEs: CVE-2003-0510 Upstream summary: A security hole exists that can be used to crash the proxy and execute arbitrary code. An exploit is circulating […]

Read more
FreeBSD 13 — py311-kerberos — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py311-kerberos — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-kerberos — DoS and MitM vulnerabilities Related CVEs: CVE-2015-3206 Upstream summary: macosforgebot reports: The checkPassword function in python-kerberos does not authenticate the KDC it attempts to communicate with, which allows […]

Read more
FreeBSD 13 — zsh — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — zsh — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zsh — Arbitrary command execution vulnerability Related CVEs: CVE-2021-45444 Upstream summary: Marc Cornellà reports: Some prompt expansion sequences, such as %F, support 'arguments' which are themselves expanded in case they […]

Read more
FreeBSD 13 — davmail — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — davmail — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 6 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: davmail — fix potential CVE-2014-3566 vulnerability (POODLE) Related CVEs: CVE-2014-3566 Upstream summary: Mickaël Guessant reports: DavMail 4.6.0 released Enhancements: Fix potential CVE-2014-3566 vulnerability. Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 13 — py39-pyrad — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py39-pyrad — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pyrad — multiple vulnerabilities Related CVEs: CVE-2013-0294 CVE-2013-0342 Upstream summary: Nathaniel McCallum reports: packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which […]

Read more
FreeBSD 13 — miniupnpc — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — miniupnpc — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: miniupnpc — integer signedness error Related CVEs: CVE-2015-6031 CVE-2017-8798 Upstream summary: Tintinweb reports: An integer signedness error was found in miniupnp's miniwget allowing an unauthenticated remote entity typically located on […]

Read more
CHAT