Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-23839

Опубликовано: 26 фев. 2024
Источник: debian
EPSS Низкий

Описание

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.response_header keyword. The vulnerability has been patched in 7.0.3. To work around the vulnerability, avoid the http.request_header and http.response_header keywords.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
suricatafixed1:7.0.3-1package
suricatanot-affectedbookwormpackage
suricatanot-affectedbullseyepackage
suricatanot-affectedbusterpackage

Примечания

  • https://github.com/OISF/suricata/security/advisories/GHSA-qxj6-hr2p-mmc7

  • https://github.com/OISF/suricata/commit/cd731fcaf42e5f7078c9be643bfa0cee2ad53e8f (suricata-7.0.3)

  • https://redmine.openinfosecfoundation.org/issues/6657

EPSS

Процентиль: 44%
0.00213
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 2 года назад

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.response_header keyword. The vulnerability has been patched in 7.0.3. To work around the vulnerability, avoid the http.request_header and http.response_header keywords.

CVSS3: 7.1
nvd
почти 2 года назад

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.response_header keyword. The vulnerability has been patched in 7.0.3. To work around the vulnerability, avoid the http.request_header and http.response_header keywords.

CVSS3: 7.1
fstec
почти 2 года назад

Уязвимость системы обнаружения и предотвращения вторжений Suricata, связанная с использованием памяти после её освобождения, позволяющая нарушителю оказать влияние на целостность и доступность защищаемой информации

EPSS

Процентиль: 44%
0.00213
Низкий