FreeBSD

FreeBSD 12 — py27-urllib — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py27-urllib — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 14 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: urllib3 — multiple vulnerabilities Related CVEs: CVE-2018-20060 CVE-2019-11236 CVE-2019-11324 Upstream summary: NIST reports: (by search in the range 2018/01/01 – 2019/11/10): urllib3 before version 1.23 does not remove the Authorization […]

Read more
FreeBSD 12 — webtrees — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — webtrees — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: webtrees — vulnerability Upstream summary: Webtrees reports: GEDCOM imports containing errors and HTML displayed unescaped. Table of contents Symptom & Impact Environment & Reproduction Root Cause Analysis Quick Triage Step-by-Step […]

Read more
FreeBSD 12 — php56-fileinfo — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php56-fileinfo — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php — multiple vulnerabilities Upstream summary: The PHP Group reports: Fileinfo: Fixed bug #71527 (Buffer over-write in finfo_open with malformed magic file). mbstring: Fixed bug #71906 (AddressSanitizer: negative-size-param (-1) in […]

Read more
FreeBSD 12 — py32-django-devel — multiple vulnerabilities (19 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py32-django-devel — multiple vulnerabilities (19 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: django — multiple vulnerabilities Related CVEs: CVE-2014-0480 CVE-2014-0481 CVE-2014-0482 CVE-2014-0483 CVE-2015-0219 CVE-2015-0220 CVE-2015-0221 CVE-2015-0222  +11 more Upstream summary: Tim Graham reports: Malicious redirect and possible XSS attack via user-supplied redirect […]

Read more
FreeBSD 12 — tdiary — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — tdiary — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tdiary — injection vulnerability Related CVEs: CVE-2006-6174 Upstream summary: An undisclosed eRuby injection vulnerability had been discovered in tDiary. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
FreeBSD 12 — irssi — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — irssi — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 13 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: irssi — Use after free when sending SASL login to the server Related CVEs: CVE-2010-1155 CVE-2010-1156 CVE-2016-7044 CVE-2016-7045 CVE-2017-10965 CVE-2017-10966 CVE-2017-15227 CVE-2017-15228  +12 more Upstream summary: Irssi reports: Use after […]

Read more
FreeBSD 12 — libzip — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libzip — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libzip — denial of service Related CVEs: CVE-2015-2331 CVE-2017-14107 Upstream summary: libzip developers report: The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers […]

Read more
FreeBSD 12 — newsgrab — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — newsgrab — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: newsgrab — insecure file and directory creation Related CVEs: CVE-2005-0153 CVE-2005-0154 Upstream summary: The newsgrab script uses insecure permissions during the creation of the local output directory and downloaded files. […]

Read more
FreeBSD 12 — plib — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — plib — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: plib — stack-based buffer overflow Related CVEs: CVE-2011-4620 CVE-2012-4552 Upstream summary: CVE reports: Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute […]

Read more
FreeBSD 12 — mariadb102-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mariadb102-server — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 March 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: MySQL Server — Multiple vulerabilities Related CVEs: CVE-2016-9843 CVE-2017-10155 CVE-2017-10165 CVE-2017-10167 CVE-2017-10203 CVE-2017-10227 CVE-2017-10268 CVE-2017-10276  +12 more Upstream summary: Oracle reports: This Critical Patch Update contains 45 new security patches […]

Read more
CHAT