Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-59149

Опубликовано: 01 окт. 2025
Источник: debian
EPSS Низкий

Описание

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In version 8.0.0, rules using keyword ldap.responses.attribute_type (which is long) with transforms can lead to a stack buffer overflow during Suricata startup or during a rule reload. This issue is fixed in version 8.0.1. To workaround this issue, users can disable rules with ldap.responses.attribute_type and transforms.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
suricatanot-affectedpackage

Примечания

  • https://github.com/OISF/suricata/security/advisories/GHSA-vxcg-38x4-gj7j

  • https://github.com/OISF/suricata/commit/38a2cba5c397002047d84645f5ab770ff88020e1 (suricata-8.0.1)

  • https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018

  • https://redmine.openinfosecfoundation.org/issues/7861

EPSS

Процентиль: 5%
0.00021
Низкий

Связанные уязвимости

CVSS3: 6.2
ubuntu
4 месяца назад

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In version 8.0.0, rules using keyword ldap.responses.attribute_type (which is long) with transforms can lead to a stack buffer overflow during Suricata startup or during a rule reload. This issue is fixed in version 8.0.1. To workaround this issue, users can disable rules with ldap.responses.attribute_type and transforms.

CVSS3: 6.2
nvd
4 месяца назад

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In version 8.0.0, rules using keyword ldap.responses.attribute_type (which is long) with transforms can lead to a stack buffer overflow during Suricata startup or during a rule reload. This issue is fixed in version 8.0.1. To workaround this issue, users can disable rules with ldap.responses.attribute_type and transforms.

CVSS3: 6.2
fstec
5 месяцев назад

Уязвимость компонента ldap.responsions.attribute_type системы обнаружения и предотвращения вторжений Suricata, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 5%
0.00021
Низкий