From nobody Thu Nov 24 20:25:45 2022 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4NJ8dP6s96z4j4YC; Thu, 24 Nov 2022 20:25:45 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4NJ8dP6LvMz40Sr; Thu, 24 Nov 2022 20:25:45 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1669321545; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=25PGWfnQTrp5ivsjTxZY58B1jfCVi13o+unAlA6xi/8=; b=NrPMVDD/PSMrWDYVEtUfSbT9qtxrAfmlA5d9VOOKOcLKuoRPaxglAopKAvywf1hI6LZkPO MqMtJfHjl3DOJ8wzBCI5WUjN1v82A8uaINTAL7tr17ylTGTVvPxq4vRPlehZrpMyEEfQpS f4qqyKPIpa45yRI1vArPdAa2Wbny794b3LdnvpwyRGG+hEODRrcVkxQG1ArxruYW8drEGL 1H/senck/5aEPEopWMGt+iD/sUOhxBu6Ln/WcOc15bHrTwv4OlRWgnFW6d2g0r0lCbn65T ONngIZRT4rlVdvsY2u5OJ5iunth/gp6IgJvsaSrmFhuHJV3WpXrqsRXJhluahQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1669321545; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=25PGWfnQTrp5ivsjTxZY58B1jfCVi13o+unAlA6xi/8=; b=FWuT75B222P+LDOK6k0xoTGlly6kIOXNWITgfjxuSU/pK47sn/VaAywje19nPPdnE1vcJP grAPe1Agi6673jgGtgDNbl9DSEUONiKyaVTdwgFqsy1v1MOZlxdqJ6INUMtHS5HulqNJtN n7blqZqRrQ5hd4iiG+/wiWS0Ql+yRTKi5SX7H1RqL2hIZIm15X9hIQ3IZrTiclE/hPPC4T 1a+FeGBumIvOd+K/IL22WtmLMqT7JsQeUMMIvDcYmLnU+Gf04u7SQ+xsiLTKCLurPkJixj sPZY9+pAu326bjbhZ2r1thv8ceooSXmnkXJwepjjWbQp6di7WRTLfBhsfioWqw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1669321545; a=rsa-sha256; cv=none; b=Dx3CBEdzskGlwt+2ev3AQQDGObK1kd6+cjz1KC9qIigNEmGeyImrMr7qsVnrFUxMS/7inD mpBPW93m7RdgweX0WlPsv8RqjrbdccgVQJ4Q4YxZzAPoZWyOvcGinjzNis6X2NUQnIWB74 OmJGx0pDVg+Fz42NEiIiG0n1YX6bnhJrpKx0ZMGvsfBviI68XjvxaBFaX2Aeu5UvNa/eJ6 Zmt56y5pruAGqkpSZfYRtkYX8gKGwXE4wZHsL3o7WKTMm6FNmRQcdgsoY4U4gP9rXeJuK2 9KEpvzbhnpsY3znaAGZD7tC19tC2XSqNP73rylUi1h52gjI3VpYhlo9RrKJryQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4NJ8dP5P3vzFTG; Thu, 24 Nov 2022 20:25:45 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 2AOKPjoW065097; Thu, 24 Nov 2022 20:25:45 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 2AOKPj7N065096; Thu, 24 Nov 2022 20:25:45 GMT (envelope-from git) Date: Thu, 24 Nov 2022 20:25:45 GMT Message-Id: <202211242025.2AOKPj7N065096@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org From: Craig Leres Subject: git: 82daa20870af - 2022Q4 - security/zeek: Update to 5.0.4 List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: leres X-Git-Repository: ports X-Git-Refname: refs/heads/2022Q4 X-Git-Reftype: branch X-Git-Commit: 82daa20870afd1194a746a689fa4d54b41f0e3e1 Auto-Submitted: auto-generated X-ThisMailContainsUnwantedMimeParts: N The branch 2022Q4 has been updated by leres: URL: https://cgit.FreeBSD.org/ports/commit/?id=82daa20870afd1194a746a689fa4d54b41f0e3e1 commit 82daa20870afd1194a746a689fa4d54b41f0e3e1 Author: Craig Leres AuthorDate: 2022-11-24 18:29:18 +0000 Commit: Craig Leres CommitDate: 2022-11-24 20:25:24 +0000 security/zeek: Update to 5.0.4 https://github.com/zeek/zeek/releases/tag/v5.0.4 This release fixes the following potential DoS vulnerabilities: - A specially-crafted series of HTTP 0.9 packets can cause Zeek to spend large amounts of time processing the packets. - A specially-crafted FTP packet can cause Zeek to spend large amounts of time processing the command. - A specially-crafted IPv6 packet can cause Zeek to overflow memory and potentially crash. This release fixes the following bugs: - Fix a potential stall in Broker’s internal data pipeline. Reported by: Tim Wojtulewicz Security: ??? (cherry picked from commit a940eea46e391fb788b2663c20ccdf6a8554fe4f) --- security/zeek/Makefile | 2 +- security/zeek/distinfo | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/security/zeek/Makefile b/security/zeek/Makefile index 0232cb4883d1..a3b18f13f64a 100644 --- a/security/zeek/Makefile +++ b/security/zeek/Makefile @@ -1,5 +1,5 @@ PORTNAME= zeek -DISTVERSION= 5.0.3 +DISTVERSION= 5.0.4 CATEGORIES= security MASTER_SITES= https://download.zeek.org/ DISTFILES= ${DISTNAME}${EXTRACT_SUFX} diff --git a/security/zeek/distinfo b/security/zeek/distinfo index 1a56ddd50ae9..f993eb2a4981 100644 --- a/security/zeek/distinfo +++ b/security/zeek/distinfo @@ -1,5 +1,5 @@ -TIMESTAMP = 1667955171 -SHA256 (zeek-5.0.3.tar.gz) = 8f16ed6b51f63f7efaca506c4ee0396b0fd03e83cb6358dbd9ea6ffe5fd0b657 -SIZE (zeek-5.0.3.tar.gz) = 42670900 +TIMESTAMP = 1669313502 +SHA256 (zeek-5.0.4.tar.gz) = d01aa72864b1128513c0b3667148e765f83cd9f0befe9a751c51f0f19a8ba280 +SIZE (zeek-5.0.4.tar.gz) = 42712052 SHA256 (zeek-zeek-netmap-v2.0.0_GH0.tar.gz) = d37a69babfbb62a51a2413d6b83ae792ce1e7f1ccb1d51bd6b209a10fe5c4d75 SIZE (zeek-zeek-netmap-v2.0.0_GH0.tar.gz) = 9100