Candidate: CVE-2015-1521 PublicDate: 2017-04-24 06:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1521 https://github.com/bro/bro/commit/6cedd67c381ff22fde653adf02ee31caf66c81a0 Description: analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not properly handle zero values of a packet length, which allows remote attackers to cause a denial of service (buffer overflow or buffer over-read if NDEBUG; otherwise assertion failure) via a crafted DNP3 packet. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_bro: upstream_bro: released (2.3.2+dfsg-1) precise_bro: DNE precise/esm_bro: DNE trusty_bro: DNE trusty/esm_bro: DNE vivid/stable-phone-overlay_bro: DNE vivid/ubuntu-core_bro: DNE xenial_bro: ignored (end of standard support, was needed) yakkety_bro: ignored (reached end-of-life) zesty_bro: ignored (reached end-of-life) artful_bro: not-affected (2.5-1) bionic_bro: not-affected (2.5-1) cosmic_bro: not-affected (2.5-1) disco_bro: not-affected (2.5-1) eoan_bro: not-affected (2.5-1) focal_bro: DNE groovy_bro: DNE hirsute_bro: DNE impish_bro: DNE jammy_bro: DNE devel_bro: DNE