FreeBSD

FreeBSD 13 — shadowsocks-libev — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — shadowsocks-libev — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: shadowsocks-libev — command injection via shell metacharacters Upstream summary: MITRE reports: Improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic. Table […]

Read more
FreeBSD 13 — zh-openoffice — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — zh-openoffice — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openoffice — DOC document heap overflow vulnerability Related CVEs: CVE-2005-0941 Upstream summary: AD-LAB reports that a heap-based buffer overflow vulnerability exists in OpenOffice's handling of DOC documents. When reading a […]

Read more
FreeBSD 13 — py39-psutil — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py39-psutil — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-psutil — double free vulnerability Related CVEs: CVE-2019-18874 Upstream summary: ret2libc reports: psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a […]

Read more
FreeBSD 13 — php55-xsl — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — php55-xsl — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 23 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2015-6834 CVE-2015-6835 CVE-2015-6836 CVE-2015-6837 CVE-2015-6838 Upstream summary: PHP reports: Core: Fixed bug #70172 (Use After Free Vulnerability in unserialize()). Fixed bug #70219 (Use after […]

Read more
FreeBSD 13 — py38-tuf — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py38-tuf — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: The Update Framwork — path traversal vulnerability Related CVEs: CVE-2021-41131 Upstream summary: NVD reports: python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and […]

Read more
FreeBSD 13 — py27-djblets — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py27-djblets — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-djblets — Self-XSS vulnerability Upstream summary: Djblets Release Notes reports: A recently-discovered vulnerability in the datagrid templates allows an attacker to generate a URL to any datagrid page containing malicious […]

Read more
FreeBSD 13 — mpack — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mpack — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mpack — Information disclosure Related CVEs: CVE-2011-4919 Upstream summary: The oss-security list reports: Incorrect permissions on temporary files can lead to information disclosure. Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 13 — compat5x-alpha — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — compat5x-alpha — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openssl — potential SSL 2.0 rollback Related CVEs: CVE-2005-2969 Upstream summary: Vulnerability: Such applications are affected if they use the option SSL_OP_MSIE_SSLV2_RSA_PADDING. This option is implied by use of SSL_OP_ALL, […]

Read more
FreeBSD 13 — bash-static — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — bash-static — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bash — remote code execution Related CVEs: CVE-2014-6271 CVE-2014-6277 CVE-2014-6278 CVE-2014-7169 CVE-2014-7186 CVE-2014-7187 Upstream summary: Note that this is different than the public "Shellshock" issue. Specially crafted environment variables could […]

Read more
FreeBSD 13 — dcraw — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — dcraw — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: dcraw — integer overflow condition Related CVEs: CVE-2015-3885 Upstream summary: ocert reports: The dcraw tool, as well as several other projects re-using its code, suffers from an integer overflow condition […]

Read more
CHAT