FreeBSD

FreeBSD 12 — halibut — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — halibut — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 January 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: halibut — Segmentation fault, denial of service or possibly other unspecified impact via a crafted text document Related CVEs: CVE-2021-42612 CVE-2021-42613 CVE-2021-42614 Upstream summary: [email protected] reports: CVE-2021-42612: A use after […]

Read more
FreeBSD 12 — crispy-doom — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — crispy-doom — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 January 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: chocolate-doom — Arbitrary code execution Related CVEs: CVE-2020-14983 Upstream summary: Michal Dardas from LogicalTrust reports: The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players […]

Read more
FreeBSD 12 — sympa — multiple vulnerabilities (5 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — sympa — multiple vulnerabilities (5 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 16 January 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sympa — Inappropriate use of the cookie parameter can be a security threat. This parameter may also not provide sufficient security. Related CVEs: CVE-2005-0073 CVE-2012-2352 CVE-2015-1306 CVE-2020-29668 CVE-2020-9369 Upstream summary: […]

Read more
FreeBSD 12 — icingaweb — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — icingaweb — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 January 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Icinga Web 2 — directory traversal vulnerability Related CVEs: CVE-2020-24368 Upstream summary: Icinga development team reports: CVE-2020-24368 Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal […]

Read more
FreeBSD 12 — x11vnc — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — x11vnc — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 9 January 2021 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: x11vnc — access to shared memory segments Related CVEs: CVE-2006-2450 CVE-2020-29074 Upstream summary: [email protected] reports: scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other […]

Read more
FreeBSD 12 — mozjpeg — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mozjpeg — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 December 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mozjpeg — heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file Related CVEs: CVE-2020-13790 Upstream summary: NIST reports: Heap-based buffer over-read in get_rgb_row() in rdppm.c via […]

Read more
FreeBSD 12 — sqlite — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — sqlite — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 8 December 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: SQLite < 3.50.3 — CWE-190 Integer Overflow or Wraparound in FTS5 module Related CVEs: CVE-2015-3414 CVE-2015-3415 CVE-2015-3416 CVE-2016-6153 CVE-2017-10989 CVE-2018-8740 CVE-2019-5018 CVE-2020-11655  +12 more Upstream summary: https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g reports: An integer […]

Read more
FreeBSD 12 — py38-bleach — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py38-bleach — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 December 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-bleach — regular expression denial-of-service Related CVEs: CVE-2020-6817 Upstream summary: Bleach developers reports: bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to […]

Read more
CHAT