FreeBSD

FreeBSD 12 — php56-mysqli — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php56-mysqli — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 December 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mysql — SSL Downgrade Related CVEs: CVE-2015-3152 Upstream summary: Duo Security reports: Researchers have identified a serious vulnerability in some versions of Oracle’s MySQL database product that allows an attacker […]

Read more
FreeBSD 12 — mt-daapd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mt-daapd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 17 December 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mt-daapd — integer overflow Related CVEs: CVE-2007-5824 CVE-2008-1771 Upstream summary: FrSIRT reports: A vulnerability has been identified in mt-daapd which could be exploited by remote attackers to cause a denial […]

Read more
FreeBSD 12 — cabextract — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — cabextract — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 17 December 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: cabextract — directory traversal with UTF-8 symbols in filenames Related CVEs: CVE-2004-0916 CVE-2014-9556 CVE-2015-2060 Upstream summary: Cabextract ChangeLog reports: It was possible for cabinet files to extract to absolute file […]

Read more
FreeBSD 12 — py32-amf — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py32-amf — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-amf — input sanitization errors Related CVEs: CVE-2015-8549 Upstream summary: oCERT reports: A specially crafted AMF payload, containing malicious references to XML external entities, can be used to trigger Denial […]

Read more
FreeBSD 12 — lifetype — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — lifetype — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lifetype — ADOdb "server.php" Insecure Test Script Security Issue Related CVEs: CVE-2006-0146 Upstream summary: Secunia reports: A security issue has been discovered in LifeType, which can be exploited by malicious […]

Read more
FreeBSD 12 — imwheel — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — imwheel — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 16 December 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: imwheel — insecure handling of PID file Upstream summary: A Computer Academic Underground advisory describes the consequences of imwheel's handling of the process ID file (PID file): imwheel exclusively uses […]

Read more
FreeBSD 12 — procmail — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — procmail — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 December 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: procmail — Heap-based buffer overflow Related CVEs: CVE-2017-16844 Upstream summary: MITRE reports: A remote attacker could use a flaw to cause formail to crash, resulting in a denial of service […]

Read more
FreeBSD 12 — racoon — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — racoon — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 December 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: racoon — remote denial-of-service Related CVEs: CVE-2004-0155 CVE-2004-0164 CVE-2004-0183 CVE-2004-0184 CVE-2004-0392 CVE-2004-0403 CVE-2005-0398 Upstream summary: Sebastian Krahmer discovered that the racoon ISAKMP daemon could be crashed with a maliciously crafted […]

Read more
FreeBSD 12 — pdfjam — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — pdfjam — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 December 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: pdfjam — insecure temporary files Related CVEs: CVE-2008-5743 Upstream summary: Secunia reports: Some security issues have been reported in PDFjam, which can be exploited by malicious, local users to perform […]

Read more
FreeBSD 12 — phpbb — multiple vulnerabilities (14 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — phpbb — multiple vulnerabilities (14 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 15 December 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: phpbb3 — multiple issues Related CVEs: CVE-2004-1315 CVE-2005-0258 CVE-2005-0259 CVE-2005-2086 CVE-2005-3310 CVE-2005-3415 CVE-2005-3416 CVE-2005-3417  +6 more Upstream summary: phpbb developers reports: Password updater working with PostgreSQL – The cron for […]

Read more
CHAT