Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-57228

Опубликовано: 18 сент. 2026
Источник: debian

Описание

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer when a quoted-printable escape sequence is split across traffic chunks and the following chunk contains exactly one byte. Crafted SMTP traffic can trigger the out-of-bounds read and crash Suricata when decode-quoted-printable MIME decoding is enabled. This issue is fixed in version 7.0.17.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
suricatafixed1:8.0.1-1package

Примечания

  • https://github.com/OISF/suricata/security/advisories/GHSA-qxm4-q7vx-7xj4

  • https://redmine.openinfosecfoundation.org/issues/8608 (suricata-7.0.17)

  • https://github.com/OISF/suricata/commit/19880f9d5bbe2b8f8e8867a577848dce2b532c86 (suricata-7.0.17)

Связанные уязвимости

CVSS3: 8.2
ubuntu
7 дней назад

[mime: buffer over read in quoted printable decoding]

CVSS3: 8.2
nvd
3 дня назад

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer when a quoted-printable escape sequence is split across traffic chunks and the following chunk contains exactly one byte. Crafted SMTP traffic can trigger the out-of-bounds read and crash Suricata when decode-quoted-printable MIME decoding is enabled. This issue is fixed in version 7.0.17.