FreeBSD

FreeBSD 12 — isc-dhcp44-relay — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — isc-dhcp44-relay — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 21 April 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: isc-dhcp — remotely exploitable vulnerability Related CVEs: CVE-2021-25217 Upstream summary: Michael McNally reports: Program code used by the ISC DHCP package to read and parse stored leases has a defect […]

Read more
FreeBSD 13 — linux-firefox-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — linux-firefox-devel — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 21 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Mozilla — multiple vulnerabilities Related CVEs: CVE-2006-3113 CVE-2006-3677 CVE-2006-3801 CVE-2006-3802 CVE-2006-3803 CVE-2006-3804 CVE-2006-3805 CVE-2006-3806  +12 more Upstream summary: The Mozilla Project reports: MFSA 2011-12 Miscellaneous memory safety hazards MFSA 2011-13 […]

Read more
FreeBSD 13 — p7zip — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — p7zip — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: p7zip — usage of uninitialized memory Related CVEs: CVE-2015-1038 CVE-2016-2334 CVE-2016-2335 CVE-2016-9296 CVE-2017-17969 CVE-2018-10115 Upstream summary: NVD reports: Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before […]

Read more
FreeBSD 13 — stunnel — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — stunnel — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 20 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: stunnel — Remote Code Execution Related CVEs: CVE-2011-2940 CVE-2013-1762 Upstream summary: Michal Trojnara reports: 64-bit versions of stunnel with the following conditions: * NTLM authentication enabled * CONNECT protocol negotiation […]

Read more
FreeBSD 13 — nwclient — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — nwclient — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 20 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: nwclient — multiple vulnerabilities Related CVEs: CVE-2001-0910 CVE-2002-0113 CVE-2002-0114 Upstream summary: Insecure file permissions, network access control and DNS usage put systems that use Legato NetWorker at risk. When the […]

Read more
FreeBSD 13 — remind — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — remind — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 19 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: remind — buffer overflow with malicious reminder file input Related CVEs: CVE-2015-5957 Upstream summary: Dianne Skoll reports: BUG FIX: Fix a buffer overflow found by Alexander Keller. The bug can […]

Read more
FreeBSD 12 — linux-flashplayer — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-flashplayer — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 19 April 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Flash Player — arbitrary code execution Related CVEs: CVE-2017-11213 CVE-2017-11215 CVE-2017-11225 CVE-2017-11281 CVE-2017-11282 CVE-2017-11292 CVE-2017-2925 CVE-2017-2926  +12 more Upstream summary: Adobe reports: This update resolves a NULL pointer dereference vulnerability […]

Read more
FreeBSD 13 — syslog-ng — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — syslog-ng — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: syslog-ng2 — startup directory leakage in the chroot environment Related CVEs: CVE-2008-5110 Upstream summary: Florian Grandel reports: I have not had the time to analyze all of syslog-ng code. But […]

Read more
FreeBSD 13 — aide — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — aide — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: aide — heap-based buffer overflow Related CVEs: CVE-2021-45417 Upstream summary: David Bouman reports: AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS […]

Read more
FreeBSD 13 — py311-tuf — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — py311-tuf — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 18 April 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: The Update Framwork — path traversal vulnerability Related CVEs: CVE-2021-41131 Upstream summary: NVD reports: python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and […]

Read more
CHAT