opnsense / ports

OPNsense ports on top of FreeBSD
https://opnsense.org/
Other
157 stars 112 forks source link

Security Audit - CVE exploits curl-7.83.1, libressl-3.3.6 #151

Closed xkpx64 closed 2 years ago

xkpx64 commented 2 years ago

_OPNsense 22.1.91-amd64 FreeBSD 13.0-STABLE LibreSSL 3.3.6

GOT REQUEST TO AUDIT SECURITY Currently running OPNsense 22.1.9_1 (amd64/LibreSSL) at Sat Jul 2 06:16:39 CEST 2022 vulnxml file up-to-date curl-7.83.1 is vulnerable: cURL -- Multiple vulnerabilities CVE: CVE-2022-32208 CVE: CVE-2022-32207 CVE: CVE-2022-32206 CVE: CVE-2022-32205 WWW: https://vuxml.FreeBSD.org/freebsd/ae5722a6-f5f0-11ec-856e-d4c9ef517024.html

libressl-3.3.6 is vulnerable: OpenSSL -- Infinite loop in BN_mod_sqrt parsing certificates CVE: CVE-2022-0778 WWW: https://vuxml.FreeBSD.org/freebsd/ea05c456-a4fd-11ec-90de-1c697aa5a594.html

2 problem(s) in 2 installed package(s) found. DONE

fichtner commented 2 years ago

Thanks, this is a useless ticket.