HomeFreeBSD

security/vuxml: Mark zeek < 4.0.6 as vulnerable as per:

Description

security/vuxml: Mark zeek < 4.0.6 as vulnerable as per:

https://github.com/zeek/zeek/releases/tag/v4.0.6
  • Fix potential unbounded state growth in the FTP analyzer when receiving a specially-crafted stream of commands. This may lead to a buffer overflow and cause Zeek to crash. Due to the possibility of this happening with packets received from the network, this is a potential DoS vulnerabilty.

Reported by: Tim Wojtulewicz

Details

Provenance
leresAuthored on Apr 21 2022, 10:43 PM
Parents
R11:21c2f510ea23: mail/spamassassin-dqs: upgrade to 1.2.2
Branches
Unknown
Tags
Unknown