diff options
author | Craig Leres <leres@FreeBSD.org> | 2020-04-14 20:55:15 +0000 |
---|---|---|
committer | Craig Leres <leres@FreeBSD.org> | 2020-04-14 20:55:15 +0000 |
commit | 67751ff7205136761272ccc885da67186a0564c4 (patch) | |
tree | fbe8a3d6cd11b8be71739c544ed9b381e1363e43 /graphics/maim | |
parent | b6d8f95ba31422e2576751b300cfb52149f7685f (diff) | |
download | ports-67751ff7205136761272ccc885da67186a0564c4.tar.gz ports-67751ff7205136761272ccc885da67186a0564c4.zip |
security/zeek: Update to 3.0.4 and address a remote crash vulnerability:
https://github.com/zeek/zeek/blob/e059d4ec2e689b3c8942f4aa08b272f24ed3f612/NEWS
- Fix stack overflow in POP3 analyzer. An attacker can crash Zeek
remotely via crafted packet sequence.
Other fixes:
- Fix use-after-free in Zeek lambda functions with uninitialized
locals
- Fix buffer overflow due to tables/records created at parse-time
not rebuilt on record redef
- Fix SMB NegotiateContextList parsing
- Fix binpac flowbuffer frame length parsing doing too much bounds
checking
- Fix parsing ERSPAN III optional sub-header
- Fix bug in intel indicator normalization
- Fix connection duration thresholding
- Fix X509Common.h header include for external plugins
- Fix incorrect targeting of node-specific Broker/Cluster messages
MFH: 2020Q2
Notes
Notes:
svn path=/head/; revision=531729
Diffstat (limited to 'graphics/maim')
0 files changed, 0 insertions, 0 deletions