Security Hardening

FreeBSD 12 — compat5x-i — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — compat5x-i — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: openssl — potential SSL 2.0 rollback Related CVEs: CVE-2005-2969 Upstream summary: Vulnerability: Such applications are affected if they use the option SSL_OP_MSIE_SSLV2_RSA_PADDING. This option is implied by use of SSL_OP_ALL, […]

Read more
FreeBSD 12 — zsync — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — zsync — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: zlib — buffer overflow vulnerability Related CVEs: CVE-2005-2096 Upstream summary: Problem Description An error in the handling of corrupt compressed data streams can result in a buffer being overflowed. Impact […]

Read more
FreeBSD 12 — portupgrade — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — portupgrade — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: portupgrade — insecure temporary file handling vulnerability Related CVEs: CVE-2005-0610 Upstream summary: Simon L. Nielsen discovered that portupgrade handles temporary files in an insecure manner. This could allow an unprivileged […]

Read more
FreeBSD 12 — newspost — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — newspost — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: newspost — server response buffer overflow vulnerability Related CVEs: CVE-2005-0101 Upstream summary: The newspost program uses a function named socket_getline to read server responses from the network socket. Unfortunately this […]

Read more
FreeBSD 12 — vtiger — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — vtiger — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: vtiger — multiple remote file inclusion vulnerabilities Related CVEs: CVE-2006-5289 Upstream summary: Dedi Dwianto a.k.a the_day reports: Input passed to the "$calpath" parameter in update.php is not properly verified before […]

Read more
FreeBSD 12 — f2c — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — f2c — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: f2c — insecure temporary files Related CVEs: CAN-2005-0017 Upstream summary: Javier Fernández-Sanguino Peña reports two temporary file vulnerability within f2c. The vulnerabilities are caused due to weak temporary file handling. […]

Read more
FreeBSD 12 — ldapscripts — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — ldapscripts — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ldapscripts — Command Line User Credentials Disclosure Related CVEs: CVE-2007-5373 Upstream summary: Ganael Laplanche reports: Up to now, each ldap* command was called with the -w parameter, which allows to […]

Read more
FreeBSD 12 — rar — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — rar — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rar — password prompt buffer overflow vulnerability Related CVEs: CVE-2007-0855 Upstream summary: iDefense reports: Remote exploitation of a stack based buffer overflow vulnerability in RARLabs Unrar may allow an attacker […]

Read more
FreeBSD 15 — powerdns — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — powerdns — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: powerdns — denial of service Related CVEs: CVE-2005-2302 CVE-2012-0206 CVE-2015-1868 CVE-2015-5230 CVE-2015-5311 CVE-2015-5470 CVE-2016-2120 CVE-2016-6170  +12 more Upstream summary: PowerDNS Team reports: PowerDNS Security Advisory 2022-01: incomplete validation of incoming […]

Read more
FreeBSD 15 — rsync — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — rsync — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: ner/rsync — multiple vulnerabilities Related CVEs: CVE-2003-0962 CVE-2004-0426 CVE-2004-0792 CVE-2007-4091 CVE-2011-1097 CVE-2016-9840 CVE-2016-9841 CVE-2016-9842  +12 more Upstream summary: The rsync project reports: Six CVEs are fixed in this release. All […]

Read more
CHAT