# Bro 2.6.4 release (security update)

**URL:** https://community.zeek.org/t/bro-2-6-4-release-security-update/5821
**Category:** Zeek
**Created:** [August 29, 2019, 12:16am UTC](https://community.zeek.org/t/bro-2-6-4-release-security-update/5821 "2019-08-29T00:16:14Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Jon\_Siwek](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@Jon\_Siwek](https://community.zeek.org/u/Jon_Siwek)
#### Post date: [August 29, 2019, 12:16am UTC](https://community.zeek.org/t/bro-2-6-4-release-security-update/5821/1 "2019-08-29T00:16:14Z")

</div>

A security patch release, Bro v2.6.4, is now available for  
download:

&nbsp;&nbsp;[https://www.zeek.org/downloads/bro-2.6.4.tar.gz](https://www.zeek.org/downloads/bro-2.6.4.tar.gz)  
&nbsp;&nbsp;[https://www.zeek.org/downloads/bro-2.6.4.tar.gz.asc](https://www.zeek.org/downloads/bro-2.6.4.tar.gz.asc)

Bro v2.6.4 addresses a potential Denial of Service  
vulnerability:

\* The NTLM analyzer did not properly handle AV Pair sequences  
&nbsp;&nbsp;that were either empty or unterminated, resulting in invalid  
&nbsp;&nbsp;memory access or heap buffer over-read. The NTLM analyzer  
&nbsp;&nbsp;is enabled by default and used in the analysis of SMB,  
&nbsp;&nbsp;DCE/RPC, and GSSAPI protocols.

&nbsp;&nbsp;Thanks to Chris Hinshaw for reporting the issue.

---

<div class="post-metadata">

### Author: ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)
#### Post date: [May 6, 2022, 3:46pm UTC](https://community.zeek.org/t/bro-2-6-4-release-security-update/5821/2 "2022-05-06T15:46:43Z")

</div>


