Описание
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not use rules with datasets save nor state options.
Ссылки
- Patch
- Patch
- Patch
- Patch
- Patch
- Patch
- Vendor Advisory
- Permissions Required
Уязвимые конфигурации
Одно из
EPSS
5.9 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
Связанные уязвимости
Suricata is a network IDS, IPS and NSM engine. While saving a dataset a stack buffer is used to prepare the data. Prior to versions 8.0.3 and 7.0.14, if the data in the dataset is too large, this can result in a stack overflow. Versions 8.0.3 and 7.0.14 contain a patch. As a workaround, do not use rules with datasets `save` nor `state` options.
Suricata is a network IDS, IPS and NSM engine. While saving a dataset ...
Уязвимость системы обнаружения и предотвращения вторжений Suricata, связанная с переполнением буфера в стеке, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5.9 Medium
CVSS3
9.8 Critical
CVSS3