XSS and OpenSSL vulnerabilities were plugged

Jun 27, 2015 09:35 GMT  ·  By

Electric Sheep Fencing, through Chris Buechler, has recently had the great pleasure of announcing that the third maintenance release of the stable pfSense 2.2 series is available for download and upgrade to all users of one of the best FreeBSD-based firewall.

According to the release notes, pfSense 2.2.3 release is here to patch many security vulnerabilities in the OpenSSL implementation, including the well-known Logjam one, as well as to fix multiple XSS vulnerabilities in pfSense's web interface (WebGUI).

In addition to those patches, pfSense 2.2.3 addresses numerous filesystem corruption issues that could occur during an unclean shutdown, for example after a power loss or a system crash.

This version also removes the forcesync patch introduced in a previous version of pfSense because it has been declared harmful to the filesystem. As a consequence, users could encounter slowness with NanoBSD.

strongSwan 5.3.2 and PHP 5.5.26 were added, many issues have been addressed in the installer for GEOM mirrors, several HTML/XHTML issues have been resolved, and limiters now work as expected when used with the IPv6 network protocol.

Last but not least, there are some improvements in Network Time Protocol (NTP), as well as in the Dynamic Host Configuration Protocol Relay Agent (DHCP/RA), Domain Name System (DNS), Common Address Redundancy Protocol (CARP), OpenVPN, and IPsec implementations.

pfSense 2.2.3 is a massive release with countless changes

Looking at the changelog, we can all agree that pfSense 2.2.3 is a massive release, not a simple maintenance version that patches some vulnerabilities and fixes a couple of those annoying issues everyone hates.

Therefore, we strongly recommend that you read those notes, something that will take you a while, if you are very curious to know what exactly has been changed in the new pfSense point release. In the meantime, you can download pfSense 2.2.3 right now from Softpedia.