Security-Onion-Solutions / security-onion

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
https://securityonion.net
3.06k stars 521 forks source link

Bro 2.6.4 #1628

Closed dougburks closed 5 years ago

dougburks commented 5 years ago
A security patch release, Bro v2.6.4, is now available for
download:

  https://www.zeek.org/downloads/bro-2.6.4.tar.gz
  https://www.zeek.org/downloads/bro-2.6.4.tar.gz.asc

Bro v2.6.4 addresses a potential Denial of Service
vulnerability:

* The NTLM analyzer did not properly handle AV Pair sequences
  that were either empty or unterminated, resulting in invalid
  memory access or heap buffer over-read.  The NTLM analyzer
  is enabled by default and used in the analysis of SMB,
  DCE/RPC, and GSSAPI protocols.
dougburks commented 5 years ago

The following packages are now ready for testing:

securityonion-bro - 2.6.4-1ubuntu1securityonion1
securityonion-bro-afpacket - 1.3.0-1ubuntu1securityonion13
securityonion-bro-scripts - 20121004-0ubuntu0securityonion73

Please test/verify as follows (watch out for line wrapping):

Please test in as many different combinations as possible:

Anything else we missed?

Please record all test results on this github issue. If everything works correctly, please record that. If not, please include detailed information about what you're experiencing.

Thanks in advance for your time and effort!

forgottentq commented 5 years ago

I ran through all the tests and everything seems to be working great!! :)

dougburks commented 5 years ago

Thanks @forgottentq !

Published: https://blog.securityonion.net/2019/09/bro-264-now-available-for-security-onion.html