OPNsense 18.7.7 released

submited 09 November 2018

Today we are addressing CVE-2018-18958 regarding an unenforced "deny config write" privilege. The issue was reported by brainrecursion this Monday and subsequently fixed along with several related issues. The "deny config write" privilege coupled with admin or user and group manager rights are affected combinations. It is an uncommon way to configureaccess as the "deny config write" privilege is commonly used for role-based access to non-system services, e.g. captive portals.

As we cannot be sure that no further issues of this sort exist please refrain from using the "deny config write" privilege or at least stop giving access to system services or full admin rights to these users or groups. In the midterm we will be looking for replacements of the current privilege for something that is more generic and robust in enforcement.

Additionally, the update to Suricata 4.0.6 addresses the SMTP crash vulnerability CVE-2018-18956. Since the update does not reboot without an operating system update please manually restart the intrusion detection service.

The BSD community linklog
Made a script? Written a blog post? Found a useful tutorial? Share it with the BSD community here or just enjoy what everyone else has found!

Submit

23 April 2024
NetBSD 9.4 available  

It represents a selected subset of fixes deemed important for security or stability reasons since the release of NetBSD 9.3 in August 2022, as well some enhancements backported from the development branch. It is fully compatible with NetBSD 9.0. Users running 9.3 or an earlier release are strongly recommended to upgrade.

FreeBSD: installing and using Haskell  

Youtube video tutorial showing how to install Haskell, setup VIM to use the Haskell Language Server and finally, write a simple program, compile it and run.

Valuable News – 2024/04/22  

The Valuable News weekly series is dedicated to provide summary about news, articles and other interesting stuff mostly but not always related to the UNIX/BSD/Linux systems.

20 April 2024
FreeBSD Foundation Delivers V1 of FreeBSD SSDF Attestation to Support Cybersecurity Compliance  

The SSDF is a key resource for entities working with the US Government, facilitating compliance with NIST SP 800-218 Section 4e as recommended by the United States Cybersecurity and Infrastructure Security Agency (CISA) in consultation with the General Services Administration (GSA) and the Office of Management and Budget (OMB). This initiative aligns with the goals of Executive Order 14028, issued by the Biden Administration in May of 2021, and Memorandum M-22-18, issued in September of 2022, aimed at enhancing national cybersecurity.

Enjoying DiscoverBSD? There is more...

Subscribe to BSD Weekly, our free, once–weekly e-mail round-up of BSD news and articles. It is currated from your content on DiscoverBSD and BSDSec (a deadsimple BSD Security Advisories and Announcements).

You can also support the work on Patreon.
19 April 2024
BSD Now 555: Poudriereing Apple Silicon  

Kubernetes and back - Why I don't run distributed systems, NetApp’s strategic contributions to FreeBSD: a deep dive into upstreaming efforts, Make your own E-Mail server - Part 2 - Adding Webmail and More with Nextcloud, Poudriere on Apple Silicon, One less Un*xy option for 32-bit PowerPC, and more.

In OpenBSD -current, default write format for tar(1) has changed  

A series of commits by Jeremie Courreges-Anglas (jca@) has modified tar(1) such that its default write format (for archives) is that of pax(1).

17 April 2024
iXsystems: No one is being ‘marooned’ by Debian focus  

Continuation of news regarding iX focusing more on Linux and less on BSD, addressing some of the concerns of BSD users.

Valuable News – 2024/04/15  

The Valuable News weekly series is dedicated to provide summary about news, articles and other interesting stuff mostly but not always related to the UNIX/BSD/Linux systems.

13 April 2024
BSDCan 2024 Travel Grant Application Now Open  

The Travel Grant Application for BSDCan 2024 is now open. The FreeBSD Foundation can help you attend BSDCan through our travel grant program. Travel grants are available to FreeBSD developers and advocates who need assistance with travel expenses for attending conferences related to FreeBSD development.

BSD Now 554: NetBSD Double Digit  

The XZ Backdoor, NetBSD 10.0, iX announces that they will put out a release of TrueNAS 13.3, State of the Terminal, LibreSSL 3.8.4 and 3.9.1 released and more.

load more