FreeBSD

FreeBSD 12 — monotone — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — monotone — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 October 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: monotone — remote denial of service in default setup Upstream summary: The monotone developers report: Running "mtn ''" or "mtn ls ''" doesn't cause an internal error anymore. In monotone […]

Read more
FreeBSD 12 — php56-gd — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — php56-gd — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 October 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libgd — integer overflow which could lead to heap buffer overflow Related CVEs: CVE-2013-7456 CVE-2015-4643 CVE-2015-4644 CVE-2015-8874 CVE-2015-8879 CVE-2016-3074 CVE-2016-4343 CVE-2016-5093  +12 more Upstream summary: LibGD reports: An integer overflow […]

Read more
FreeBSD 12 — ircd-ratbox — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ircd-ratbox — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 24 October 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ircd-ratbox and charybdis — remote DoS vulnerability Related CVEs: CVE-2009-4016 CVE-2010-0300 Upstream summary: atheme.org reports: All versions of Charybdis are vulnerable to a remotely-triggered crash bug caused by code originating […]

Read more
FreeBSD 12 — subversion-freebsd — multiple vulnerabilities (7 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — subversion-freebsd — multiple vulnerabilities (7 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 22 October 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Subversion — multiple vulnerabilities Related CVEs: CVE-2009-2411 CVE-2010-4539 CVE-2010-4644 CVE-2011-0715 CVE-2011-1752 CVE-2011-1783 CVE-2011-1921 Upstream summary: Subversion team reports: Subversion's mod_dav_svn Apache HTTPD server module will dereference a NULL pointer if […]

Read more
FreeBSD 12 — isc-dhcp3-server — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — isc-dhcp3-server — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 October 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: isc-dhcpd — format string vulnerabilities Related CVEs: CVE-2004-0460 CVE-2004-1006 Upstream summary: The ISC DHCP programs are vulnerable to several format string vulnerabilities which may allow a remote attacker to execute […]

Read more
FreeBSD 12 — xrdb — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — xrdb — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 October 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: xrdb — root hole via rogue hostname Related CVEs: CVE-2011-0465 Upstream summary: Matthias Hopf reports: By crafting hostnames with shell escape characters, arbitrary commands can be executed in a root […]

Read more
FreeBSD 12 — zh-tin — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — zh-tin — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 October 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tin — buffer overflow vulnerabilities Upstream summary: Urs Janssen and Aleksey Salow report possible buffer overflows in tin versions 1.8.0 and 1.8.1. OpenPKG project elaborates there is an allocation off-by-one […]

Read more
FreeBSD 12 — tdiary-devel — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — tdiary-devel — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 22 October 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: tdiary — injection vulnerability Related CVEs: CVE-2006-6174 Upstream summary: An undisclosed eRuby injection vulnerability had been discovered in tDiary. Table of contents Symptom & Impact Environment & Reproduction Root Cause […]

Read more
CHAT