Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-38535

Опубликовано: 11 июл. 2024
Источник: debian

Описание

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 traffic. Upgrade to 6.0.20 or 7.0.6.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
suricatafixed1:7.0.6-1package
suricatano-dsabookwormpackage
suricatano-dsabullseyepackage

Примечания

  • https://github.com/OISF/suricata/security/advisories/GHSA-cg8j-7mwm-v563

  • https://github.com/OISF/suricata/commit/62d5cac1b8483d5f9d2b79833a4e59f5d80129b7 (suricata-6.0.20)

  • https://github.com/OISF/suricata/commit/c82fa5ca0d1ce0bd8f936e0b860707a6571373b2 (suricata-7.0.6)

  • https://redmine.openinfosecfoundation.org/issues/7105

  • https://redmine.openinfosecfoundation.org/issues/7112

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 traffic. Upgrade to 6.0.20 or 7.0.6.

CVSS3: 7.5
nvd
больше 1 года назад

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 traffic. Upgrade to 6.0.20 or 7.0.6.