FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-23 14:57:51 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
ad4d3871-1a0d-11e5-b43d-002590263bf5logstash-forwarder and logstash -- susceptibility to POODLE vulnerability

Elastic reports:

The combination of Logstash Forwarder and Lumberjack input (and output) was vulnerable to the POODLE attack in SSLv3 protocol. We have disabled SSLv3 for this combination and set the minimum version to be TLSv1.0. We have added this vulnerability to our CVE page and are working on filling out the CVE.

Thanks to Tray Torrance, Marc Chadwick, and David Arena for reporting this.

SSLv3 is no longer supported; TLS 1.0+ is required (compatible with Logstash 1.4.2+).


Discovery 2015-06-09
Entry 2015-06-24
Modified 2015-06-24
logstash-forwarder
< 0.4.0.20150507

logstash
< 1.4.3

ports/201065
ports/201065
https://www.elastic.co/blog/logstash-1-4-3-released
https://www.elastic.co/blog/logstash-forwarder-0-4-0-released