FreeBSD

FreeBSD 13 — rssh — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rssh — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 21 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rssh – multiple vulnerabilities Related CVEs: CVE-2004-0609 CVE-2005-3345 CVE-2012-3478 CVE-2019-1000018 CVE-2019-3463 CVE-2019-3464 Upstream summary: NVD reports: rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a […]

Read more
FreeBSD 13 — openfire — multiple vulnerabilities (10 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — openfire — multiple vulnerabilities (10 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Openfire administration console authentication bypass Related CVEs: CVE-2008-1728 CVE-2008-6508 CVE-2008-6509 CVE-2008-6510 CVE-2008-6511 CVE-2009-0496 CVE-2009-0497 CVE-2009-1595  +2 more Upstream summary: [email protected] reports: Openfire's administrative console, a web-based application, was found to […]

Read more
FreeBSD 13 — py27-pycrypto — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py27-pycrypto — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pycrypto — PRNG reseed race condition Related CVEs: CVE-2013-1445 Upstream summary: Dwayne Litzenberger reports: In PyCrypto before v2.6.1, the Crypto.Random pseudo-random number generator (PRNG) exhibits a race condition that may […]

Read more
FreeBSD 13 — rkhunter — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rkhunter — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rkhunter — insecure temporary file creation Related CVEs: CVE-2005-1270 Upstream summary: Gentoo reports: Sune Kloppenborg Jeppesen and Tavis Ormandy of the Gentoo Linux Security Team have reported that the check_update.sh […]

Read more
FreeBSD 13 — mysql55-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mysql55-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL — multiple vulnerabilities Related CVEs: CVE-2015-3194 CVE-2015-4792 CVE-2015-4802 CVE-2015-4807 CVE-2015-4815 CVE-2015-4826 CVE-2015-4830 CVE-2015-4836  +12 more Upstream summary: Oracle reports: Please reference CVE/URL list for details Not all listed CVE's […]

Read more
FreeBSD 13 — diablo-jre — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — diablo-jre — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: jdk/jre — Security Vulnerability With Java Plugin Related CVEs: CVE-2004-1029 Upstream summary: The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does […]

Read more
FreeBSD 13 — apache+mod_ssl+mod_snmp+mod_deflate+ipv — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — apache+mod_ssl+mod_snmp+mod_deflate+ipv — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: apache — Prevent chunk-size integer overflow on platforms where sizeof(int) < sizeof(long) Related CVEs: CVE-2005-2088 CVE-2005-3352 CVE-2006-3747 Upstream summary: Apache ChangeLog reports: Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c […]

Read more
FreeBSD 13 — pear-Net_Ping — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — pear-Net_Ping — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PEAR — Net_Ping and Net_Traceroute remote arbitrary command injection Related CVEs: CVE-2009-4024 CVE-2009-4025 Upstream summary: PEAR Security Advisory reports: Multiple remote arbitrary command injections have been found in the Net_Ping […]

Read more
FreeBSD 13 — ossec-hids-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ossec-hids-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: security/ossec-hids-* — root escalation via syscheck feature Related CVEs: CVE-2014-5284 CVE-2015-3222 Upstream summary: OSSEC reports: The CVE-2015-3222 vulnerability, which allows for root escalation via sys check has been fixed in […]

Read more
FreeBSD 13 — libtool — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libtool — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libtool — Library Search Path Privilege Escalation Issue Related CVEs: CVE-2009-3736 Upstream summary: Secunia.com Do not attempt to load an unqualified module.la file from the current directory (by default) since […]

Read more
CHAT