FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-11-23 17:01:17 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
388ebb5b-3c95-11eb-929d-d4c9ef517024Unbound/NSD -- Denial of service vulnerability

NLNetLabs reports:

Unbound and NSD when writing the PID file would not check if an existing file was a symlink. This could allow for a local symlink \ attack if an attacker has access to the user Unbound/NSD runs as.


Discovery 2020-12-01
Entry 2020-12-12
unbound
< 1.13.0

nsd
< 4.3.4

https://nlnetlabs.nl/downloads/unbound/CVE-2020-28935.txt
CVE-2020-28935
56778a31-c2a1-11e9-9051-4c72b94353b5nsd -- Stack-based Buffer Overflow

SO-AND-SO reports:

nsd-checkzone in NLnet Labs NSD 4.2.0 has a Stack-based Buffer Overflow in the dname_concatenate() function in dname.c.


Discovery 2019-07-28
Entry 2019-08-19
nsd
< 4.2.2

https://nvd.nist.gov/vuln/detail/CVE-2019-13207
https://github.com/NLnetLabs/nsd/issues/20
CVE-2019-13207