Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-64335

Опубликовано: 26 нояб. 2025
Источник: debian

Описание

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
suricatafixed1:8.0.2-1package
suricatanot-affectedtrixiepackage
suricatanot-affectedbookwormpackage
suricatanot-affectedbullseyepackage

Примечания

  • https://github.com/OISF/suricata/security/advisories/GHSA-v299-h7p3-q4f2

  • https://redmine.openinfosecfoundation.org/issues/7959

  • Fixed by: https://github.com/OISF/suricata/commit/c935f08cd988600fd0a4f828a585b181dd5de012 (suricata-8.0.2)

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

CVSS3: 7.5
nvd
2 месяца назад

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость системы обнаружения и предотвращения вторжений Suricata, связанная с разыменованием указателей, позволяющая нарушителю вызвать отказ в обслуживании