HomeFreeBSD

security/zeek: Update to 3.0.8 and address various vulnerabilities:

Description

security/zeek: Update to 3.0.8 and address various vulnerabilities:

https://github.com/zeek/zeek/releases/tag/v3.0.8
  • Fix potential DNS analyzer stack overflow
  • Fix potential NetbiosSSN analyzer stack overflow

Other fixes:

  • Fix DHCP Client ID Option misformat for Hardware Type 0
  • Fix/allow copying/cloning of opaque of Broker::Store
  • Fix ConnPolling memory over-use
  • Fix compress_path not normalizing some paths correctly
  • Fix integer conversion error for Tag subtypes/enums
  • Fix bro_prng() results not staying within modulus
  • Prevent providing a 0 seed to bro_prng() since the LCG parameters don't allow that

Reported by: Jon Siwek
MFH: 2020Q3
Security: e333084c-9588-4eee-8bdc-323e02cb4fe0

Details

Provenance
leresAuthored on
Parents
rP543559: security/vuxml: Mark zeek < 3.0.8 as vulnerable as per:
Branches
Unknown
Tags
Unknown