Page Menu
Home
FreeBSD
Search
Configure Global Search
Log In
Files
F140057104
D16948.id47462.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Flag For Later
Award Token
Size
2 KB
Referenced Files
None
Subscribers
None
D16948.id47462.diff
View Options
Index: security/vuxml/vuln.xml
===================================================================
--- security/vuxml/vuln.xml
+++ security/vuxml/vuln.xml
@@ -58,6 +58,57 @@
* Do not forget port variants (linux-f10-libxml2, libxml2, etc.)
-->
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
+ <vuln vid="d0be41fe-2a20-4633-b057-4e8b25c41780">
+ <topic>bro -- array bounds and potential DOS issues</topic>
+ <affects>
+ <package>
+ <name>bro</name>
+ <range><lt>2.5.5</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Corelight reports:</p>
+ <blockquote cite="https://www.bro.org/download/NEWS.bro.html">
+ <p>Bro 2.5.5 primarily addresses security issues:</p>
+ <ul>
+ <li>Fix array bounds checking in BinPAC: for arrays
+ that are fields within a record, the bounds check was
+ based on a pointer to the start of the record rather
+ than the start of the array field, potentially resulting
+ in a buffer over-read.</li>
+ <li>Fix SMTP command string comparisons: the number
+ of bytes compared was based on the user-supplied
+ string length and can lead to incorrect matches. e.g.
+ giving a command of "X" incorrectly matched
+ "X-ANONYMOUSTLS" (and an empty commands match
+ anything).</li>
+ </ul>
+ <p>Address potential vectors for Denial of Service:</p>
+ <ul>
+ <li>"Weird" events are now generally suppressed/sampled
+ by default according to some tunable parameters.</li>
+ <li>Improved handling of empty lines in several text
+ protocol analyzers that can cause performance issues
+ when seen in long sequences.</li>
+ <li>Add `smtp_excessive_pending_cmds' weird which
+ serves as a notification for when the "pending command"
+ queue has reached an upper limit and been cleared to
+ prevent one from attempting to slowly exhaust
+ memory.</li>
+ </ul>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <url>https://www.bro.org/download/NEWS.bro.html</url>
+ </references>
+ <dates>
+ <discovery>2018-08-28</discovery>
+ <entry>2018-08-29</entry>
+ </dates>
+ </vuln>
+
<vuln vid="0904e81f-a89d-11e8-afbb-bc5ff4f77b71">
<topic>node.js -- multiple vulnerabilities</topic>
<affects>
File Metadata
Details
Attached
Mime Type
text/plain
Expires
Sat, Dec 20, 3:55 PM (15 h, 2 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
27098574
Default Alt Text
D16948.id47462.diff (2 KB)
Attached To
Mode
D16948: security/vuxml: Mark bro < 2.5.5 as vulnerable
Attached
Detach File
Event Timeline
Log In to Comment