HomeFreeBSD

security/zeek: Update to 5.0.2

Description

security/zeek: Update to 5.0.2

https://github.com/zeek/zeek/releases/tag/v5.0.2

Security fixes:

  • Fix a possible overflow and crash in the ICMP analyzer when receiving a specially crafted packet
  • Fix a possible overflow and crash in the IRC analyzer when receiving a specially crafted packet
  • Fix a possible overflow and crash in the SMB analyzer when receiving a specially crafted packet
  • Fix two possible crashes when converting IP headers for output via the raw_packet event

Other changes:

  • Fix a bug that prevented Broker nodes to recover from OpenSSL errors.
  • Fix handling of buffer sizes that caused Broker to stall despite having sufficient capacity.
  • Fix an issue with signal handling that could prevent Zeek from exiting via ctrl-c when reading scripts from stdin.

Also fix new PR 266345 issue reported by @pkubaj ("fails to build
without SPICY enabled").

PR: 266345
Reported by: Tim Wojtulewicz, pkubaj

Details

Provenance
leresAuthored on Sep 20 2022, 12:02 AM
Parents
R11:d14b56623a58: security/vuxml: Mark zeek < 5.0.2 as vulnerable as per:
Branches
Unknown
Tags
Unknown