Candidate: CVE-2017-1000458 PublicDate: 2018-01-02 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000458 https://bro-tracker.atlassian.net/browse/BIT-1856 https://github.com/bro/bro/commit/6c0f101a62489b1c5927b4ed63b0e1d37db40282 Description: Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploitation. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_bro: upstream: https://github.com/bro/bro/commit/6c0f101a62489b1c5927b4ed63b0e1d37db40282 upstream_bro: released (2.5.2-1) precise/esm_bro: DNE trusty_bro: DNE trusty/esm_bro: DNE xenial_bro: ignored (end of standard support, was needed) zesty_bro: ignored (reached end-of-life) artful_bro: ignored (reached end-of-life) bionic_bro: not-affected (2.5.3-1build1) cosmic_bro: not-affected (2.5.3-1build1) disco_bro: not-affected (2.5.3-1build1) eoan_bro: not-affected (2.5.3-1build1) focal_bro: DNE groovy_bro: DNE hirsute_bro: DNE impish_bro: DNE jammy_bro: DNE devel_bro: DNE