FreeBSD Bugzilla – Attachment 158029 Details for
Bug 201065
sysutils/logstash-forwarder: [security] Request update to 0.4.0 to resolve SSLv3 security concerns
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
security/vuxml entry for logstash-forwarder/logstash
logstash-forwarder_vuxml.diff (text/plain), 1.93 KB, created by
Jason Unovitch
on 2015-06-24 01:25:17 UTC
(
hide
)
Description:
security/vuxml entry for logstash-forwarder/logstash
Filename:
MIME Type:
Creator:
Jason Unovitch
Created:
2015-06-24 01:25:17 UTC
Size:
1.93 KB
patch
obsolete
>Index: vuln.xml >=================================================================== >--- vuln.xml (revision 390366) >+++ vuln.xml (working copy) >@@ -57,6 +57,48 @@ > > --> > <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> >+ <vuln vid="ad4d3871-1a0d-11e5-b43d-002590263bf5"> >+ <topic>logstash-forwarder and logstash -- Susceptibility to POODLE Vulnerability</topic> >+ <affects> >+ <package> >+ <name>logstash-forwarder</name> >+ <range><lt>0.4.0.20150507</lt></range> >+ </package> >+ <package> >+ <name>logstash</name> >+ <range><lt>1.4.3</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>Elastic reports:</p> >+ <blockquote cite="https://www.elastic.co/blog/logstash-1-4-3-released"> >+ <p>The combination of Logstash Forwarder and Lumberjack input (and >+ output) was vulnerable to the POODLE attack in SSLv3 protocol. We >+ have disabled SSLv3 for this combination and set the minimum version >+ to be TLSv1.0. We have added this vulnerability to our CVE page and >+ are working on filling out the CVE.</p> >+ <p>Thanks to Tray Torrance, Marc Chadwick, and David Arena for >+ reporting this.</p> >+ </blockquote> >+ <blockquote cite="https://www.elastic.co/blog/logstash-forwarder-0-4-0-released"> >+ <p>SSLv3 is no longer supported; TLS 1.0+ is required (compatible >+ with Logstash 1.4.2+).</p> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <freebsdpr>ports/201065</freebsdpr> >+ <freebsdpr>ports/201065</freebsdpr> >+ <url>https://www.elastic.co/blog/logstash-1-4-3-released</url> >+ <url>https://www.elastic.co/blog/logstash-forwarder-0-4-0-released</url> >+ </references> >+ <dates> >+ <discovery>2015-06-09</discovery> >+ <entry>2015-06-24</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="f5225b23-192d-11e5-a1cf-002590263bf5"> > <topic>rubygem-bson -- DoS and possible injection</topic> > <affects>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 201065
:
158013
|
158014
| 158029