FreeBSD

FreeBSD 13 — py35-yaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py35-yaml — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-yaml — FullLoader (still) exploitable for arbitrary command execution Related CVEs: CVE-2017-18342 CVE-2020-1747 Upstream summary: Riccardo Schirone (https://github.com/ret2libc) reports: In FullLoader python/object/new constructor, implemented by construct_python_object_apply, has support for setting […]

Read more
FreeBSD 13 — jftpgw — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — jftpgw — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Arbitrary code execution via a format string vulnerability in jftpgw Related CVEs: CVE-2004-0448 Upstream summary: The log functions in jftpgw may allow remotely authenticated user to execute arbitrary code via […]

Read more
FreeBSD 13 — silc-irssi-client — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — silc-irssi-client — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: silc-client — Format string vulnerability Related CVEs: CVE-2009-3051 Upstream summary: SILC changelog reports: An unspecified format string vulnerability exists in silc-client. Table of contents Symptom & Impact Environment & Reproduction […]

Read more
FreeBSD 13 — intel-nvmupdate — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — intel-nvmupdate — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Intel(R) NVMUpdate — Intel(R) Ethernet Controller X710/XL710 NVM Security Vulnerability Related CVEs: CVE-2016-8106 Upstream summary: Intel Corporation reports: A security vulnerability in the Intel(R) Ethernet Controller X710 and Intel(R) Ethernet […]

Read more
FreeBSD 13 — lsh — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — lsh — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lsh — multiple vulnerabilities Related CVEs: CVE-2003-0826 CVE-2005-0814 Upstream summary: Secunia reports: A vulnerability has been reported in LSH, which potentially can be exploited by malicious people to cause a […]

Read more
FreeBSD 13 — isc-dhcp41-server — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — isc-dhcp41-server — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: isc-dhcpd — Denial of Service Related CVEs: CVE-2010-3611 CVE-2011-0413 CVE-2011-2748 CVE-2011-2749 CVE-2011-4539 CVE-2012-3570 CVE-2012-3571 CVE-2012-3954  +1 more Upstream summary: ISC reports: A badly formed packet with an invalid IPv4 UDP […]

Read more
FreeBSD 13 — bftpd — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — bftpd — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bftpd — Multiple vulnerabilities Upstream summary: Bftpd project reports: Bftpd is vulnerable to out of bounds memory access, file descriptor leak and a potential buffer overflow. Table of contents Symptom […]

Read more
FreeBSD 13 — shibboleth2-sp — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — shibboleth2-sp — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: shibboleth2-sp — "Dynamic" metadata provider plugin issue Upstream summary: The Internet2 community reports: The Shibboleth Service Provider software includes a MetadataProvider plugin with the plugin type "Dynamic" to obtain metadata […]

Read more
FreeBSD 13 — ko-helvis — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ko-helvis — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: helvis — arbitrary file deletion problem Related CVEs: CVE-2005-0118 CVE-2005-0119 CVE-2005-0120 Upstream summary: The setuid root elvprsv utility, used to preserve recovery helvis files, can be abused by local users […]

Read more
FreeBSD 13 — phpmyadmin — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — phpmyadmin — multiple vulnerabilities (20 CVEs) — patch and remediation guide (PATCH-REMEDIATION-2)

🟠 High   ⏱ 15–60 min  Last verified: 3 October 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: phpmyadmin — multiple vulnerabilities Related CVEs: CVE-2005-0543 CVE-2005-0544 CVE-2005-0567 CVE-2005-0653 CVE-2005-0992 CVE-2007-6100 CVE-2016-1927 CVE-2016-2038  +12 more Upstream summary: the phpmyadmin team reports: This security fix is part of an ongoing […]

Read more
CHAT