FreeBSD

FreeBSD 13 — mariadb-connector-c — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mariadb-connector-c — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MariaDB — Vulnerability in C API Related CVEs: CVE-2020-2574 Upstream summary: MariaDB reports: Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. […]

Read more
FreeBSD 13 — apache+mod_perl — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — apache+mod_perl — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Apache 1.3 — mod_proxy reverse proxy exposure Related CVEs: CVE-2004-0940 CVE-2005-2088 CVE-2005-3352 CVE-2006-3747 CVE-2011-3368 Upstream summary: Apache HTTP server project reports: An exposure was found when using mod_proxy in reverse […]

Read more
FreeBSD 13 — kf5-kauth — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — kf5-kauth — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: kf5-kauth — Insecure handling of arguments in helpers Related CVEs: CVE-2017-8422 CVE-2019-7443 Upstream summary: Albert Astals Cid reports: KAuth allows to pass parameters with arbitrary types to helpers running as […]

Read more
FreeBSD 13 — tinc-devel — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — tinc-devel — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tinc — Buffer overflow Related CVEs: CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 Upstream summary: tinc-vpn.org reports: The authentication protocol allows an oracle attack that could potentially be exploited. If a man-in-the-middle has intercepted […]

Read more
FreeBSD 13 — codeigniter — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — codeigniter — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: codeigniter — input validation bypass Upstream summary: The CodeIgniter changelog reports: Security: Fixed a potential object injection in Cache Library 'apc' driver when save() is used with $raw = TRUE. […]

Read more
FreeBSD 13 — phplist — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — phplist — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: phpList — SQL injection and XSS vulnerability Related CVEs: CVE-2009-0422 CVE-2012-2740 CVE-2012-2741 Upstream summary: Zero Science Lab reports: Input passed via the parameter 'sortby' is not properly sanitised before being […]

Read more
FreeBSD 13 — linux-c7-libssh — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-c7-libssh — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libssh2 — multiple issues Related CVEs: CVE-2019-3855 CVE-2019-3856 CVE-2019-3857 CVE-2019-3858 CVE-2019-3859 CVE-2019-3860 CVE-2019-3861 CVE-2019-3862  +1 more Upstream summary: libssh2 developers report: Defend against possible integer overflows in comp_method_zlib_decomp. Defend against […]

Read more
FreeBSD 13 — zh-chitex — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — zh-chitex — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ChiTeX/ChiLaTeX unsafe set-user-id root Upstream summary: Niels Heinen reports that ChiTeX installs set-user-id root executables that invoked system(3) without setting up the environment, trivially allowing local root compromise. Table of […]

Read more
FreeBSD 13 — linux_base-c6_ — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux_base-c6_ — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: glibc — getaddrinfo stack-based buffer overflow Related CVEs: CVE-2015-7547 Upstream summary: Fabio Olive Leite reports: A stack-based buffer overflow was found in libresolv when invoked from nss_dns, allowing specially crafted […]

Read more
FreeBSD 13 — py39-twisted — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py39-twisted — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 July 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-twisted — cookie and authorization headers are leaked when following cross-origin redirects Upstream summary: Twisted developers report: Cookie and Authorization headers are leaked when following cross-origin redirects in twited.web.client.RedirectAgent and […]

Read more
CHAT