跳转到帖子

FreeBSD: VID-96D6809A-81DF-46D4-87ED-2F78C79F06B1: zeek -- potential DoS vulnerabilities

recommended_posts

发布于
  • Members

FreeBSD: VID-96D6809A-81DF-46D4-87ED-2F78C79F06B1: zeek -- potential DoS vulnerabilities

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
04/12/2023
Created
05/05/2023
Added
04/14/2023
Modified
04/14/2023

Description

Tim Wojtulewicz of Corelight reports:

Receiving DNS responses from async DNS requests (via

A specially-crafted stream of FTP packets containing a

command reply with many intermediate lines can cause Zeek

to spend a large amount of time processing data.

A specially-crafted set of packets containing extremely

large file offsets cause cause the reassembler code to

allocate large amounts of memory.

The DNS manager does not correctly expire responses

that don't contain any data, such those containing NXDOMAIN

or NODATA status codes. This can lead to Zeek allocating

large amounts of memory for these responses and never

deallocating them.

A specially-crafted stream of RDP packets can cause

Zeek to spend large protocol validation.

A specially-crafted stream of SMTP packets can cause

Zeek to spend large amounts of time processing data.

Solution(s)

  • freebsd-upgrade-package-zeek
  • 查看数 701
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…