Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability: Regex matching in ruleset #185

Closed
mardom1 opened this issue Feb 17, 2021 · 3 comments
Closed

Security vulnerability: Regex matching in ruleset #185

mardom1 opened this issue Feb 17, 2021 · 3 comments
Assignees
Milestone

Comments

@mardom1
Copy link

mardom1 commented Feb 17, 2021

We found a vulnerability in the way regex expressions are matched in rules.

What is the proper way to disclose such vulnerabilities?

@michaelweiser michaelweiser self-assigned this Feb 17, 2021
@michaelweiser
Copy link
Contributor

Thanks for the report. You can send an email with the details to security@peekabooav.de.

@michaelweiser michaelweiser transferred this issue from scVENUS/PeekabooAV Feb 18, 2021
@michaelweiser
Copy link
Contributor

We have received your detailed information. We have reproduced the issue and are working on a fix. I will make this issue confidential for now. It will be restored to public access for further tracking and documentation once a fix is released. If you have any further comments or details you can send them to security@peekabooav.de as before. Thank you!

@michaelweiser michaelweiser transferred this issue from another repository Feb 19, 2021
@michaelweiser michaelweiser added this to the 2.1 milestone Feb 19, 2021
@michaelweiser
Copy link
Contributor

The issue has been fixed in development by commit a839b79. This change is part of release 2.0.1, available since yesterday afternoon at https://github.com/scVENUS/PeekabooAV/releases/tag/v2.0.1. Thanks for your report and detailed analysis, @mardom1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants