This page displays vulnerability information about FreeBSD Ports.
The VUXML data was last processed by FreshPorts on 2025-01-25 14:24:43 UTC
List all Vulnerabilities, by package
List all Vulnerabilities, by date
k68These are the vulnerabilities relating to the commit you have selected:
VuXML ID | Description |
---|---|
c62285cb-cb46-11ee-b609-002590c1f29c | FreeBSD -- bhyveload(8) host file accessProblem Description:`bhyveload -h Impact:In the bhyveload(8) model, the host supplies a userboot.so to boot with, but the loader scripts generally come from the guest image. A maliciously crafted script could be used to exfiltrate sensitive data from the host accessible to the user running bhyhveload(8), which is often the system root. Discovery 2024-02-14 Entry 2024-02-14 FreeBSD >= 14.0 lt 14.0_5 >= 13.2 lt 13.2_10 CVE-2024-25940 SA-24:01.bhyveload |