FreeBSD

FreeBSD 13 — rubygem19-rack — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem19-rack — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Ruby Rack Gem — Multiple Issues Related CVEs: CVE-2013-0262 CVE-2013-0263 Upstream summary: Rack developers report: Today we are proud to announce the release of Rack 1.4.5. Fix CVE-2013-0263, timing attack […]

Read more
FreeBSD 13 — linux-c7-graphite — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-c7-graphite — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 23 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: graphite2 — out-of-bounds write with malicious font Related CVEs: CVE-2017-5436 Upstream summary: Mozilla Foundation reports: An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. […]

Read more
FreeBSD 13 — freerdp — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — freerdp — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 23 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: freerdp — clients using the `/video` command line switch might read uninitialized data Related CVEs: CVE-2020-11017 CVE-2020-11018 CVE-2020-11019 CVE-2020-11038 CVE-2020-11039 CVE-2020-11040 CVE-2020-11041 CVE-2020-11043  +12 more Upstream summary: MITRE reports: All […]

Read more
FreeBSD 13 — libsrtp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — libsrtp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libsrtp — DoS via crafted RTP header vulnerability Related CVEs: CVE-2015-6360 Upstream summary: libsrtp reports: Prevent potential DoS attack due to lack of bounds checking on RTP header CSRC count […]

Read more
FreeBSD 13 — openvpn-polarssl — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — openvpn-polarssl — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: OpenVPN — out-of-bounds write in legacy key-method 1 Related CVEs: CVE-2017-12166 CVE-2017-7478 CVE-2017-7479 CVE-2017-7508 CVE-2017-7512 CVE-2017-7520 CVE-2017-7521 CVE-2017-7522 Upstream summary: Steffan Karger reports: The bounds check in read_key() was performed […]

Read more
FreeBSD 13 — mkvtoolnix — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mkvtoolnix — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mkvtoolnix — code execution via specially crafted files Upstream summary: Moritz Bunkus reports: most of the bugs fixed on 2016-09-06 and 2016-09-07 for issue #1780 are potentially exploitable. The scenario […]

Read more
FreeBSD 13 — rubygem-rack — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem-rack — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 22 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rack — possible denial of service vulnerability in header parsing Related CVEs: CVE-2011-4815 CVE-2011-4838 CVE-2011-5036 CVE-2011-5037 CVE-2015-1840 CVE-2015-3224 CVE-2015-3225 CVE-2015-3226  +7 more Upstream summary: ooooooo_q reports: Carefully crafted input can […]

Read more
FreeBSD 13 — postfixadmin — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — postfixadmin — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: postfixadmin — SQL injection vulnerability Related CVEs: CVE-2012-0811 CVE-2012-0812 CVE-2014-2655 Upstream summary: Thijs Kinkhorst reports: Postfixadmin has an SQL injection vulnerability. This vulnerability is only exploitable by authenticated users able […]

Read more
FreeBSD 13 — rubygem-rexml — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — rubygem-rexml — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ruby — XML round-trip vulnerability in REXML Related CVEs: CVE-2021-28965 Upstream summary: Juho Nurminen reports: When parsing and serializing a crafted XML document, REXML gem (including the one bundled with […]

Read more
FreeBSD 13 — tmux — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — tmux — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tmux — stack overflow in CSI parsing Upstream summary: Nicholas Marriott reports: tmux has a stack overflow in CSI parsing. Table of contents Symptom & Impact Environment & Reproduction Root […]

Read more
CHAT