FreeBSD

FreeBSD 12 — atril-lite — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — atril-lite — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 3 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: evince and atril — command injection vulnerability in CBT handler Related CVEs: CVE-2017-1000083 Upstream summary: GNOME reports: The comic book backend in evince 3.24.0 (and earlier) is vulnerable to a […]

Read more
FreeBSD 12 — lesstif — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — lesstif — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xpm — image decoding vulnerabilities Related CVEs: CVE-2004-0687 CVE-2004-0688 Upstream summary: Chris Evans discovered several vulnerabilities in the libXpm image decoder: A stack-based buffer overflow in xpmParseColors An integer overflow […]

Read more
FreeBSD 12 — libgcrypt — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libgcrypt — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libgcrypt — ECDSA timing attack Related CVEs: CVE-2013-4242 CVE-2015-7511 CVE-2016-6313 CVE-2017-0379 CVE-2017-7526 CVE-2018-0495 CVE-2019-13627 Upstream summary: GnuPG reports: Mitigate an ECDSA timing attack. Table of contents Symptom & Impact Environment […]

Read more
FreeBSD 12 — egroupware — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — egroupware — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: egroupware — two vulnerabilities Related CVEs: CVE-2005-1202 CVE-2005-1203 Upstream summary: Egroupware Team report: Nahuel Grisolia from CYBSEC S.A. Security Systems found two security problems in EGroupware: Serious remote command execution […]

Read more
FreeBSD 12 — amaya — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — amaya — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: amaya — multiple buffer overflow vulnerabilities Related CVEs: CVE-2006-1900 CVE-2008-5282 CVE-2009-0323 Upstream summary: Secunia reports: A boundary error when processing "div" HTML tags can be exploited to cause a stack-based […]

Read more
FreeBSD 12 — typo — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — typo — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: typo3 — Missing access check in Extbase Related CVEs: CVE-2007-1081 CVE-2009-0255 CVE-2009-0256 CVE-2009-0257 CVE-2009-0258 CVE-2009-0815 CVE-2009-0816 CVE-2009-3628  +12 more Upstream summary: TYPO3 reports: Extbase request handling fails to implement a […]

Read more
FreeBSD 12 — py39-Elixir — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py39-Elixir — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py39-Elixir — weak use of cryptography Related CVEs: CVE-2012-2146 Upstream summary: Red Hat Security Response Team reports: Elixir 0.8.0 uses Blowfish in CFB mode without constructing a unique initialization vector […]

Read more
FreeBSD 12 — gnomevfs — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — gnomevfs — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 2 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gnomevfs — unsafe URI handling Related CVEs: CVE-2004-0494 Upstream summary: Alexander Larsson reports that some versions of gnome-vfs and MidnightCommander contain a number of `extfs' scripts that do not properly […]

Read more
FreeBSD 12 — uwsgi — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — uwsgi — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: uwsgi — a stack-based buffer overflow Related CVEs: CVE-2018-6758 Upstream summary: Uwsgi developers report: It was discovered that the uwsgi_expand_path function in utils.c in Unbit uWSGI, an application container server, […]

Read more
FreeBSD 12 — xinetd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — xinetd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 1 February 2020 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xinetd — ignores user and group directives for TCPMUX services Related CVEs: CVE-2012-0862 CVE-2013-4342 Upstream summary: xinetd would execute configured TCPMUX services without dropping privilege to match the service configuration […]

Read more
CHAT