FreeBSD

FreeBSD 12 — py39-unicorn — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py39-unicorn — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 May 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py39-unicorn — sandbox escape and arbitrary code execution vulnerability Related CVEs: CVE-2021-44078 Upstream summary: jwang-a reports: An issue was discovered in split_region in uc.c in Unicorn Engine before 2.0.0-rc5. It […]

Read more
FreeBSD 13 — consul — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — consul — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 12 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: consul — rpc: authorize raft requests Related CVEs: CVE-2017-15133 CVE-2020-25864 CVE-2020-28053 CVE-2021-28156 CVE-2021-37219 Upstream summary: Hashicorp reports: HashiCorp Consul Raft RPC layer allows non-server agents with a valid certificate signed […]

Read more
FreeBSD 13 — ap22-mod_jk — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ap22-mod_jk — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mod_jk — information disclosure Related CVEs: CVE-2014-8111 Upstream summary: NIST reports: Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers […]

Read more
FreeBSD 13 — ja-groff — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — ja-groff — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: groff — pic2graph and eqn2graph are vulnerable to symlink attack through temporary files Related CVEs: CVE-2004-0969 CVE-2004-1296 Upstream summary: The eqn2graph and pic2graph scripts in groff 1.18.1 allow local users […]

Read more
FreeBSD 13 — mysql-scripts — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mysql-scripts — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mysql-scripts — mysqlaccess insecure temporary file creation Related CVEs: CVE-2004-0457 CVE-2005-0004 Upstream summary: The Debian Security Team reports: Javier Fernández-Sanguino Peña from the Debian Security Audit Project discovered a temporary […]

Read more
FreeBSD 13 — lukemftpd — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — lukemftpd — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tnftpd — remotely exploitable vulnerability Related CVEs: CVE-2004-0794 Upstream summary: lukemftpd(8) is an enhanced BSD FTP server produced within the NetBSD project. The sources for lukemftpd are shipped with some […]

Read more
FreeBSD 13 — gnu-radius — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — gnu-radius — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gnu-radius — SNMP-related denial-of-service Related CVEs: CVE-2004-0849 Upstream summary: An iDEFENSE security advisory reports: Remote exploitation of an input validation error in version 1.2 of GNU radiusd could allow a […]

Read more
FreeBSD 13 — dante — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — dante — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: fd_set — bitmap index overflow in multiple applications Upstream summary: 3APA3A reports: If programmer fails to check socket number before using select() or fd_set macros, it's possible to overwrite memory […]

Read more
FreeBSD 13 — xdeview — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — xdeview — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 May 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: uudeview buffer overflows Upstream summary: The authors of UUDeview report repairing two buffer overflows in their software. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick […]

Read more
CHAT