From nobody Mon Jan 22 18:07:50 2024 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4TJdVb5mvWz57vJg; Mon, 22 Jan 2024 18:07:51 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4TJdVb3sH3z4pSJ; Mon, 22 Jan 2024 18:07:51 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1705946871; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=mQjMZQMzMeYG6NRyQmso/ZVp2iXDfCcceuyzxVWmklM=; b=BUMq8QtF0AuH+4aVAUdMivZ2j/GS84xtl6FKg9CLbjLaqipTe4Cg3+io7V6ucN/6KOkUQK 7Ig4tF/cxMcnX0iGECMSYjwgAE683Ppe16RYCOd1Pduw08AOh81qvKw3CTrcLrYnzrEHAT mtQKX0negm6er0LQCbWWb5oGKCH0npuCOIixhrl3Dv8BcwqriQxY4g8RgnYkDgQLM/4jF7 MHfz2bKmEFqmQeP1ZKpuLoQXYdyVji9pM/3zXYy8VENUhhg7bxmLTq+otSaOQ8Wo06wJ8k Cfp95zBbPCEpThPzcdLQQRDQluy2K5XMwEJaqTTp1b4Q+Zei40c8faD+dwr6aw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1705946871; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=mQjMZQMzMeYG6NRyQmso/ZVp2iXDfCcceuyzxVWmklM=; b=amwQTRfMDGqJfAm67KG6c44YlGdRn4MV3mrO0PrPm/7KZkNL3b9m2tU/U/Q7+9KJXUDKHW WYQ12sBULlY12yAVpH1rr1dKs8fLgpwpsvBkduvRl9wGr/cdSV1iFCuyR1lJuPfaJIKnvS o+Qa13Gjd/2wyu7O0mFr4RqIr6zRA4b49y113xG9LeNYru1tsaI3d6a0VxttSCUBnlbfdY Y+UNGNNTceATE7WOdDnl/wh7XztJeB66ywjxKuHa+eZmcQuW1A8sBFSMp/FR6qp5u1nepO ltJXxcxWjcN631eKMZb4KUEFbkc/nhFGl5HMZoR0BCOZ2CW0xuuyqQeT+hc7UA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1705946871; a=rsa-sha256; cv=none; b=o12Ha+ymF65dyGqg3/ppzf0ikOptDmscW8mjPp8Xn/B/x38RgGNmXHK2DDnV9oDkUFxIlu kyttaH5L5H4IPAgt7KnMD02n4uE8Mvhgtnf1PFUoiUsY5lXSv+tLmBHIpfIQS4c/lcqgdR 7hUJSU5oh07UFmXcNE+04tX8e0jQ/IUyTnpsl0M6hfhb3bmxjC42kPxKP2XyBSjZSKSeX7 QHs5j+R6oD3JosU68TVec/wVEkMOgSVECf2pp2/i1DkpEGEgCCdOWpLnKChR36ow4OpXks 3ZhCgLE6vllDdY91Eqsd+f8IrUhf0v7n/oMle5sinW4IuU6IvxI6TGDfztFO8A== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4TJdVZ6vtxz1BhX; Mon, 22 Jan 2024 18:07:50 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 40MI7oIm076462; Mon, 22 Jan 2024 18:07:50 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 40MI7ohg076459; Mon, 22 Jan 2024 18:07:50 GMT (envelope-from git) Date: Mon, 22 Jan 2024 18:07:50 GMT Message-Id: <202401221807.40MI7ohg076459@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org From: Craig Leres Subject: git: c0b438490e79 - 2024Q1 - security/zeek: Update to 6.0.3 List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: leres X-Git-Repository: ports X-Git-Refname: refs/heads/2024Q1 X-Git-Reftype: branch X-Git-Commit: c0b438490e791057088b3867c48ddc3c1628ba1f Auto-Submitted: auto-generated The branch 2024Q1 has been updated by leres: URL: https://cgit.FreeBSD.org/ports/commit/?id=c0b438490e791057088b3867c48ddc3c1628ba1f commit c0b438490e791057088b3867c48ddc3c1628ba1f Author: Craig Leres AuthorDate: 2024-01-22 17:53:28 +0000 Commit: Craig Leres CommitDate: 2024-01-22 18:07:32 +0000 security/zeek: Update to 6.0.3 https://github.com/zeek/zeek/releases/tag/v6.0.3 This release fixes the following potential DoS vulnerability: - A specially-crafted series of packets containing nested MIME entities can cause Zeek to spend large amounts of time parsing the entities. This release fixes the following bugs: - CMake correctly passes along third-party package information when building plugins. - Fix a problem with the HTTP analyzer where a signature regex ending in '$' used to match against 'http-request-body' or 'http-reply-bdoy' will never succeed. - The DNS analyzer now understands the Ed25519 and Ed448 signature algorithms. - The SMB::State$recent_files field was not correctly expiring entries, leading to unbounded state growth. - The &create_expire attribute is now kept valid after clearing a table. Reported by: Tim Wojtulewicz Security: fedf7e71-61bd-49ec-aaf0-6da14bdbb319 (cherry picked from commit e81dfaab6a0511eeb704adfffeb68c6be034bb4c) --- security/zeek/Makefile | 3 +-- security/zeek/distinfo | 6 +++--- security/zeek/pkg-plist | 2 ++ 3 files changed, 6 insertions(+), 5 deletions(-) diff --git a/security/zeek/Makefile b/security/zeek/Makefile index 79b7ba0eed14..b2c0bc260b52 100644 --- a/security/zeek/Makefile +++ b/security/zeek/Makefile @@ -1,6 +1,5 @@ PORTNAME= zeek -DISTVERSION= 6.0.2 -PORTREVISION= 1 +DISTVERSION= 6.0.3 CATEGORIES= security MASTER_SITES= https://download.zeek.org/ DISTFILES= ${DISTNAME}${EXTRACT_SUFX} diff --git a/security/zeek/distinfo b/security/zeek/distinfo index 2f9b2eae87e8..677c0645e529 100644 --- a/security/zeek/distinfo +++ b/security/zeek/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1698437165 -SHA256 (zeek-6.0.2.tar.gz) = 2421989adcee6a29f48a8f7272f719edbe954d66c2e86e3a52e79cae177f887c -SIZE (zeek-6.0.2.tar.gz) = 60175209 +TIMESTAMP = 1705944333 +SHA256 (zeek-6.0.3.tar.gz) = 227edf0e1e6b54dc9893cfd1ecd8621291cc85d1d06808874394aad555f8a8a4 +SIZE (zeek-6.0.3.tar.gz) = 60225127 diff --git a/security/zeek/pkg-plist b/security/zeek/pkg-plist index d7c06b5f6092..c009aca9bf16 100644 --- a/security/zeek/pkg-plist +++ b/security/zeek/pkg-plist @@ -739,6 +739,7 @@ include/zeek/analyzer/protocol/login/Telnet.h include/zeek/analyzer/protocol/login/events.bif.h include/zeek/analyzer/protocol/login/functions.bif.h include/zeek/analyzer/protocol/mime/MIME.h +include/zeek/analyzer/protocol/mime/consts.bif.h include/zeek/analyzer/protocol/mime/events.bif.h include/zeek/analyzer/protocol/modbus/Modbus.h include/zeek/analyzer/protocol/modbus/events.bif.h @@ -1379,6 +1380,7 @@ share/man/man8/zeek.8.gz %%DATADIR%%/base/bif/plugins/Zeek_KRB.types.bif.zeek %%DATADIR%%/base/bif/plugins/Zeek_Login.events.bif.zeek %%DATADIR%%/base/bif/plugins/Zeek_Login.functions.bif.zeek +%%DATADIR%%/base/bif/plugins/Zeek_MIME.consts.bif.zeek %%DATADIR%%/base/bif/plugins/Zeek_MIME.events.bif.zeek %%DATADIR%%/base/bif/plugins/Zeek_MQTT.events.bif.zeek %%DATADIR%%/base/bif/plugins/Zeek_MQTT.types.bif.zeek