Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploitation.
[
{
"id": "CVE-2017-1000458-96f05b51",
"deprecated": false,
"digest": {
"length": 1285.0,
"function_hash": "314230704580117239620428961814389718311"
},
"signature_version": "v1",
"target": {
"function": "ContentLine_Analyzer::DoDeliverOnce",
"file": "src/analyzer/protocol/tcp/ContentLine.cc"
},
"signature_type": "Function",
"source": "https://github.com/bro/bro/commit/6c0f101a62489b1c5927b4ed63b0e1d37db40282"
},
{
"id": "CVE-2017-1000458-d3372ac2",
"deprecated": false,
"digest": {
"line_hashes": [
"252986685978261559604287061895409808001",
"157222507407568721352694592129854957913",
"21707835919630023512851080404486787951",
"274180513845098636242285476533097899499"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "src/analyzer/protocol/tcp/ContentLine.cc"
},
"signature_type": "Line",
"source": "https://github.com/bro/bro/commit/6c0f101a62489b1c5927b4ed63b0e1d37db40282"
}
]