aboutsummaryrefslogtreecommitdiff
path: root/sysutils/rustic/Makefile
diff options
context:
space:
mode:
authorCraig Leres <leres@FreeBSD.org>2026-08-19 20:09:40 +0000
committerCraig Leres <leres@FreeBSD.org>2026-08-19 20:09:40 +0000
commita2cc1eae85b117805cd331d9f7bd2446be875cfb (patch)
treeb2a11d6c74f846db6a8b8909ce4e539677697be5 /sysutils/rustic/Makefile
parentcbe03aa7584bab489c7d0bdf2720a35b7459375a (diff)
security/zeek: Update to 8.0.10HEADmain
https://github.com/zeek/zeek/releases/tag/v8.0.10 This release fixes the following vulnerabilities: - HIGH: SMB: Chains of AndX messages can crash Zeek - HIGH: DNP3: Memory exhaustion via file control (g70v1) fields - HIGH: SIP: Memory exhaustion from long request/response paths - HIGH: DHCP: Memory exhaustion from retained options after analyzer violation - HIGH: SMTP: Memory exhaustion from large numbers of rcptto/to/cc/path entries - HIGH: SMB: DCE/RPC memory exhaustion from fragment state - HIGH: Analyzer manager: Equivalent scheduled analyzers could exhaust memory - HIGH: ZIP: Unbounded decompression - HIGH: Redis: Parsed Redis traffic memory exhaustion - HIGH: Invalid IPv6 fragments can lead to unbounded state growth - HIGH: SSH: Quadratic KEX algorithm CPU exhaustion - HIGH: NVT: Oversized line recovery writes before heap buffer - HIGH: DHCP: Unbounded state growth via join_data - HIGH: FTP: Unbounded state growth via ftp_data_expected - HIGH: OCSP: Empty byName responder ID crashes Zeek - HIGH: ARP: Tunneled ARP traffic crashes Zeek - HIGH: LDAP: Unbounded per-connection script state - HIGH: IRC DCC SEND has unbounded state growth - HIGH: tunnel_changed event limit bypass on direct/tunneled toggles - HIGH: Recursive stack exhaustion from deep packet analyzer chains - MEDIUM: Telnet: AUTH STATUS options before a NAME is received results in event argument mismatch - MEDIUM: UDP: udp_contents events could trigger out-of-bounds reads - MEDIUM: NetBIOS: Memory exhaustion from declared session lengths - MEDIUM: IRC: Single DCC Send packet can result in scripting error - MEDIUM: IRC: Invalid DCC Send host/port fields can lead to unexpected parsing results This release fixes the following bugs: - IN_ANYWHERE is now allowed as a wildcard in Intel files for the interface field. - The Prometheus service discovery endpoint for the telemetry framework was not rendering IPv6 addresses correctly. The unknown_protocols.log previously included the IP next protocol - field as a 16 bit value, with the first byte value set to the next protocol followed by a zero byte due to a spurious use of htons(). - Fixed file descriptors of the WebSocket server and WebSocket client connections (Cluster::listen_websocket()) being inherited by child processes. E.g., when using system() in Zeek scripts or the Input Framework's raw reader functionality. Reported by: Tim Wojtulewicz Security: e6a17802-cda9-4f53-8870-b629e4ac3d40
Diffstat (limited to 'sysutils/rustic/Makefile')
0 files changed, 0 insertions, 0 deletions