FreeBSD

FreeBSD 12 — imlib2-nox — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — imlib2-nox — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: imlib2 — XPM processing buffer overflow vulnerability Related CVEs: CVE-2008-5187 Upstream summary: Secunia reports: A vulnerability has been discovered in imlib2, which can be exploited by malicious people to potentially […]

Read more
FreeBSD 12 — phpldapadmin-php — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — phpldapadmin-php — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: phpldapadmin — XSS vulnerability Related CVEs: CVE-2020-35132 Upstream summary: [email protected] reports: An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may […]

Read more
FreeBSD 12 — trojita — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — trojita — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mail/trojita — may leak mail contents (not user credentials) over unencrypted connection Related CVEs: CVE-2014-2567 Upstream summary: Jan Kundrát reports: An SSL stripping vulnerability was discovered in Trojitá, a fast […]

Read more
FreeBSD 12 — zh-emacs — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — zh-emacs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 14 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: emacs — movemail format string vulnerability Related CVEs: CVE-2005-0100 Upstream summary: Max Vozeler discovered several format string vulnerabilities in the movemail utility of Emacs. They can be exploited when connecting […]

Read more
FreeBSD 12 — transmission-daemon — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — transmission-daemon — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: transmission-daemon — vulnerable to dns rebinding attacks Upstream summary: Google Project Zero reports: The transmission bittorrent client uses a client/server architecture, the user interface is the client which communicates to […]

Read more
FreeBSD 12 — py37-urllib — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py37-urllib — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 13 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: urllib3 — multiple vulnerabilities Related CVEs: CVE-2018-20060 CVE-2019-11236 CVE-2019-11324 Upstream summary: NIST reports: (by search in the range 2018/01/01 – 2019/11/10): urllib3 before version 1.23 does not remove the Authorization […]

Read more
FreeBSD 12 — phpAdsNew — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — phpAdsNew — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 13 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pear-XML_RPC — remote PHP code injection vulnerability Related CVEs: CVE-2005-2498 Upstream summary: A Hardened-PHP Project Security Advisory reports: When the library parses XMLRPC requests/responses, it constructs a string of PHP […]

Read more
FreeBSD 12 — py310-twisted — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py310-twisted — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-twisted — cookie and authorization headers are leaked when following cross-origin redirects Upstream summary: Twisted developers report: Cookie and Authorization headers are leaked when following cross-origin redirects in twited.web.client.RedirectAgent and […]

Read more
FreeBSD 12 — sudosh — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — sudosh — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sudosh — buffer overflow Upstream summary: ISS reports: sudosh2 and sudosh3 are vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the replay() function. By persuading a […]

Read more
FreeBSD 12 — kronolith — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — kronolith — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: kronolith — arbitrary local file inclusion vulnerability Upstream summary: iDefense Labs reports: Remote exploitation of a design error in Horde's Kronolith could allow an authenticated web mail user to execute […]

Read more
CHAT