FreeBSD

FreeBSD 13 — py36-gunicorn — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py36-gunicorn — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-gunicorn — CWE-113 vulnerability Related CVEs: CVE-2018-1000164 Upstream summary: Everardo reports: gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in process_headers function in […]

Read more
FreeBSD 13 — mariadb-client — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mariadb-client — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL – Multiple vulnerabilities Related CVEs: CVE-2015-4792 CVE-2015-4802 CVE-2015-4807 CVE-2015-4815 CVE-2015-4826 CVE-2015-4830 CVE-2015-4836 CVE-2015-4858  +3 more Upstream summary: Oracle reports: Critical Patch Update: MySQL Server, version(s) 5.5.45 and prior, 5.6.26 […]

Read more
FreeBSD 13 — py35-django-devel — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py35-django-devel — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: django — multiple vulnerabilities Related CVEs: CVE-2016-2048 CVE-2016-2512 CVE-2016-2513 Upstream summary: Tim Graham reports: Malicious redirect and possible XSS attack via user-supplied redirect URLs containing basic auth User enumeration through […]

Read more
FreeBSD 13 — gstreamer-ffmpeg — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — gstreamer-ffmpeg — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 3 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ffmpeg — multiple vulnerabilities Related CVEs: CVE-2011-3892 CVE-2011-3893 CVE-2011-3895 CVE-2011-3929 CVE-2011-3936 CVE-2011-3937 CVE-2011-3940 CVE-2011-3945  +12 more Upstream summary: NVD reports: The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 does […]

Read more
FreeBSD 13 — py39-salt — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py39-salt — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: salt — multiple vulnerabilities Related CVEs: CVE-2020-28243 CVE-2020-28972 CVE-2020-35662 CVE-2021-25281 CVE-2021-25282 CVE-2021-25283 CVE-2021-25284 CVE-2021-3144  +2 more Upstream summary: SaltStack reports multiple security vulnerabilities in Salt CVE-2021-3197: The Salt-API.s SSH client […]

Read more
FreeBSD 12 — py36-salt — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py36-salt — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 December 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: salt — multiple vulnerabilities Related CVEs: CVE-2017-12791 CVE-2017-14695 CVE-2017-14696 CVE-2018-15750 CVE-2018-15751 CVE-2019-17361 CVE-2020-11651 CVE-2020-11652  +12 more Upstream summary: SaltStack reports multiple security vulnerabilities in Salt CVE-2021-3197: The Salt-API.s SSH client […]

Read more
FreeBSD 13 — cryptopp — multiple vulnerabilities (4 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — cryptopp — multiple vulnerabilities (4 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 1 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: cryptopp — ElGamal implementation allows plaintext recovery Related CVEs: CVE-2015-2141 CVE-2016-3995 CVE-2016-7420 CVE-2021-40530 Upstream summary: Crypto++ 8.6 release notes reports: The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery […]

Read more
FreeBSD 13 — tcpslice — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — tcpslice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tcpslice — heap-based use-after-free in extract_slice() Related CVEs: CVE-2021-41043 Upstream summary: The Tcpdump Group reports: heap-based use-after-free in extract_slice() Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 13 — sieve-connect — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — sieve-connect — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 December 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sieve-connect — TLS hostname verification was not occurring Upstream summary: sieve-connect developer Phil Pennock reports: sieve-connect was not actually verifying TLS certificate identities matched the expected hostname. Table of contents […]

Read more
CHAT