FreeBSD

FreeBSD 12 — gstreamer1-libav — multiple vulnerabilities (11 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — gstreamer1-libav — multiple vulnerabilities (11 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 12 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ffmpeg — multiple vulnerabilities Related CVEs: CVE-2015-3395 CVE-2015-3417 CVE-2015-6818 CVE-2015-6819 CVE-2015-6820 CVE-2015-6821 CVE-2015-6822 CVE-2015-6823  +3 more Upstream summary: NVD reports: The decode_ihdr_chunk function in libavcodec/pngdec.c in FFmpeg before 2.7.2 does […]

Read more
FreeBSD 12 — torrentflux — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — torrentflux — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: torrentflux — User-Agent XSS Vulnerability Related CVEs: CVE-2006-5227 Upstream summary: Steven Roddis reports that User-Agent string is not properly escaped when handled by torrentflux. This allows for arbitrary code insertion. […]

Read more
FreeBSD 12 — mathopd — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — mathopd — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mathopd — directory traversal vulnerability Upstream summary: Michiel Boland reports: The software has a vulnerability that could lead to directory traversal if the '*' construct for mass virtual hosting is […]

Read more
FreeBSD 12 — shibboleth-sp — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — shibboleth-sp — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 12 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Shibboleth Service Provider — SQL injection vulnerability in ODBC plugin Related CVEs: CVE-2015-2684 Upstream summary: Internet2 reports: The Shibboleth Service Provider includes a storage API usable for a number of […]

Read more
FreeBSD 12 — ircd-ratbox-devel — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ircd-ratbox-devel — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: irc-ratbox — multiple vulnerabilities Related CVEs: CVE-2009-4016 CVE-2010-0300 Upstream summary: SecurityFocus reports: The first affects the /quote HELP module and allows a user to trigger an IRCD crash on some […]

Read more
FreeBSD 12 — py37-requests — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py37-requests — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: www/py-requests — Information disclosure vulnerability Upstream summary: The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which […]

Read more
FreeBSD 12 — py33-amf — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py33-amf — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-amf — input sanitization errors Related CVEs: CVE-2015-8549 Upstream summary: oCERT reports: A specially crafted AMF payload, containing malicious references to XML external entities, can be used to trigger Denial […]

Read more
FreeBSD 12 — libmad — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — libmad — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 11 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libmad — multiple vulnerabilities Related CVEs: CVE-2017-8372 CVE-2017-8373 CVE-2017-8374 Upstream summary: National Vulnerability Database: CVE-2017-8372: The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b, if NDEBUG is omitted, allows […]

Read more
FreeBSD 12 — py310-psutil — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py310-psutil — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 11 September 2019 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-psutil — double free vulnerability Related CVEs: CVE-2019-18874 Upstream summary: ret2libc reports: psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a […]

Read more
CHAT