FreeBSD

FreeBSD 12 — kf5-kio — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — kf5-kio — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 May 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: kio: Information Leak when accessing https when using a malicious PAC file Upstream summary: Albert Astals Cid reports: Using a malicious PAC file, and then using exfiltration methods in the […]

Read more
FreeBSD 12 — diablo-jdk — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — diablo-jdk — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 May 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: jdk — jar directory traversal vulnerability Related CVEs: CVE-2004-1029 CVE-2005-1080 Upstream summary: Pluf has discovered a vulnerability in Sun Java JDK/SDK, which potentially can be exploited by malicious people to […]

Read more
FreeBSD 12 — ruby22-gems — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ruby22-gems — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 28 May 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygems — deserialization vulnerability Related CVEs: CVE-2015-3900 CVE-2017-0903 Upstream summary: oss-security mailing list: There is a possible unsafe object desrialization vulnerability in RubyGems. It is possible for YAML deserialization of […]

Read more
FreeBSD 12 — mod_pubcookie — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mod_pubcookie — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 May 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mod_pubcookie — cross site scripting vulnerability Upstream summary: Nathan Dors of the Pubcookie Project reports: Non-persistent XSS vulnerabilities were found in the Pubcookie Apache module (mod_pubcookie) and ISAPI filter. These […]

Read more
FreeBSD 12 — py37-yaml — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py37-yaml — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 May 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PyYAML — arbitrary code execution Related CVEs: CVE-2017-18342 CVE-2020-14343 CVE-2020-1747 Upstream summary: A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary […]

Read more
FreeBSD 12 — rubygem-passenger — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rubygem-passenger — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 27 May 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rubygem-passenger — arbitrary file read vulnerability Related CVEs: CVE-2013-2119 CVE-2015-7519 CVE-2017-16355 Upstream summary: Phusion reports: The cPanel Security Team discovered a vulnerability in Passenger that allows users to list the […]

Read more
FreeBSD 12 — py311-beaker — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py311-beaker — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 27 May 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-beaker — arbitrary code execution vulnerability Related CVEs: CVE-2013-7489 Upstream summary: matheusbrat reports: The Beaker library through 1.12.1 for Python is affected by deserialization of untrusted data, which could lead […]

Read more
FreeBSD 12 — linux-openmotif — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-openmotif — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 May 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xpm — image decoding vulnerabilities Related CVEs: CVE-2004-0687 CVE-2004-0688 Upstream summary: Chris Evans discovered several vulnerabilities in the libXpm image decoder: A stack-based buffer overflow in xpmParseColors An integer overflow […]

Read more
FreeBSD 12 — libproxy — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libproxy — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 May 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libproxy — stack-based buffer overflow Related CVEs: CVE-2012-4504 Upstream summary: Tomas Hoger reports: A buffer overflow flaw was discovered in the libproxy's url::get_pac() used to download proxy.pac proxy auto-configuration file. […]

Read more
FreeBSD 12 — yii — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — yii — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 26 May 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: yii — Remote arbitrary PHP code execution Related CVEs: CVE-2014-4672 Upstream summary: Yii PHP Framework developers report: We are releasing Yii 1.1.15 to fix a security issue found in 1.1.14. […]

Read more
CHAT