FreeBSD

FreeBSD 13 — php4-cli — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — php4-cli — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Related CVEs: CVE-2004-0594 CVE-2004-0595 CVE-2004-1019 CVE-2004-1065 CVE-2005-0596 CVE-2006-4481 CVE-2006-4482 CVE-2006-4483  +12 more Upstream summary: The PHP development team reports: Security Enhancements and Fixes in PHP 5.2.2 […]

Read more
FreeBSD 13 — png — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — png — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 20 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: png — CWE-122: Heap-based Buffer Overflow Related CVEs: CVE-2004-0421 CVE-2004-0597 CVE-2004-0598 CVE-2004-0599 CVE-2007-2445 CVE-2007-5266 CVE-2007-5267 CVE-2007-5268  +12 more Upstream summary: https://github.com/pnggroup/libpng/security/advisories/GHSA-g8hp-mq4h-rqm3 reports: LIBPNG is a reference library for use in […]

Read more
FreeBSD 13 — phpicalendar — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — phpicalendar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: phpicalendar — cross site scripting vulnerability Related CVEs: CVE-2005-3366 Upstream summary: Francesco Ongaro reports that phpicalendar is vulnerable for a cross site scripting attack. The vulnerability is caused by improper […]

Read more
FreeBSD 13 — firefox-ja — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — firefox-ja — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mozilla — code execution via Quicktime media-link files Related CVEs: CVE-2006-4965 CVE-2006-6077 CVE-2007-0008 CVE-2007-0009 CVE-2007-0775 CVE-2007-0776 CVE-2007-0777 CVE-2007-0778  +11 more Upstream summary: The Mozilla Foundation reports a vulnerability within the […]

Read more
FreeBSD 13 — p5-Crypt-OpenPGP — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — p5-Crypt-OpenPGP — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gnupg — OpenPGP symmetric encryption vulnerability Related CVEs: CVE-2005-0366 Upstream summary: Serge Mister and Robert Zuccherato reports that the OpenPGP protocol is vulnerable to a cryptographic attack when using symmetric […]

Read more
FreeBSD 13 — gpgme — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — gpgme — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gpgme — heap-based buffer overflow in gpgsm status handler Related CVEs: CVE-2014-3564 Upstream summary: Tomas Trnka reports: Gpgme contains a buffer overflow in the gpgsm status handler that could possibly […]

Read more
FreeBSD 13 — logstash-forwarder — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — logstash-forwarder — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: logstash-forwarder and logstash — susceptibility to POODLE vulnerability Upstream summary: Elastic reports: The combination of Logstash Forwarder and Lumberjack input (and output) was vulnerable to the POODLE attack in SSLv3 […]

Read more
FreeBSD 12 — py310-nicotine-plus — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py310-nicotine-plus — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 July 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-nicotine-plus — Denial of service vulnerability Related CVEs: CVE-2021-45848 Upstream summary: ztauras reports: Denial of service (DoS) vulnerability in Nicotine+ starting with version 3.0.3 and prior to version 3.2.1 allows […]

Read more
FreeBSD 13 — rubygem-activesupport — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem-activesupport — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 18 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Rails — multiple vulnerabilities Related CVEs: CVE-2007-3227 CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 CVE-2013-0155 CVE-2013-0156 CVE-2013-1854 CVE-2013-1856  +12 more Upstream summary: Ruby on Rails blog: Hi everyone! Rails 5.2.4.3 and 6.0.3.1 have been […]

Read more
FreeBSD 12 — rubygem-date — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rubygem-date — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 July 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-date — Regular Expression Denial of Service Vunlerability of Date Parsing Methods Related CVEs: CVE-2021-41817 Upstream summary: Stanislav Valkanov reports: Date's parsing methods including Date.parse are using Regexps internally, some […]

Read more
CHAT