HomeFreeBSD

security/zeek: Update to 7.0.2

Description

security/zeek: Update to 7.0.2

https://github.com/zeek/zeek/releases/tag/v7.0.2

This release fixes the following potential DoS vulnerability:

  • The POP3 parser has been hardened to avoid unbounded state growth in the face of one-sided traffic capture or when enabled for non-POP3 traffic.

This release fixes the following bugs:

  • Support for SASL+SPNEGO+NTLMSSP was added to the LDAP analyzer.
  • Telemetry callbacks are now handled via Zeek instead of depending on the prometehus-cpp library to handle them.

Reported by: Tim Wojtulewicz

Details

Provenance
leresAuthored on Sep 24 2024, 5:46 AM
Parents
R11:f3bf10dd60b6: security/vuxml: Mark zeek < 7.0.2 as vulnerable as per:
Branches
Unknown
Tags
Unknown