跳转到帖子

FreeBSD: VID-7A425536-74F7-4CE4-9768-0079A9D44D11: zeek -- potential DoS vulnerabilities

recommended_posts

发布于
  • Members

FreeBSD: VID-7A425536-74F7-4CE4-9768-0079A9D44D11: zeek -- potential DoS vulnerabilities

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
02/21/2023
Created
02/24/2023
Added
02/23/2023
Modified
02/23/2023

Description

Tim Wojtulewicz of Corelight reports:

Receiving DNS responses from async DNS requests (via

the lookup_addr, etc BIF methods) with the TTL set to

zero could cause the DNS manager to eventually stop being

able to make new requests.

Specially-crafted FTP packets with excessively long

usernames, passwords, or other fields could cause log

writes to use large amounts of disk space.

The find_all and find_all_ordered BIF methods could

take extremely large amounts of time to process incoming

data depending on the size of the input.

Solution(s)

  • freebsd-upgrade-package-zeek
  • 查看数 696
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…