Libfetch FreeBSD Libfetch

Do you want an email whenever new security vulnerabilities are reported in FreeBSD Libfetch?

By the Year

In 2024 there have been 0 vulnerabilities in FreeBSD Libfetch . Libfetch did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 1 9.10
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Libfetch vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent FreeBSD Libfetch Security Vulnerabilities

libfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and HTTP protocols

CVE-2021-36159 9.1 - Critical - August 03, 2021

libfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and HTTP protocols. The FTP passive mode implementation allows an out-of-bounds read because strtol is used to parse the relevant numbers into address bytes. It does not check if the line ends prematurely. If it does, the for-loop condition checks for the '\0' terminator one byte too late.

Out-of-bounds Read

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for FreeBSD Libfetch or by FreeBSD? Click the Watch button to subscribe.

FreeBSD
Vendor

subscribe