Suricata是Open Information Security基金会的一个网络IDS、IPS和NSM引擎。 Suricata 7.0.8之前版本存在安全漏洞,该漏洞源于无符号整数下溢,在使用memset初始化期间用零填充时,特制的TCP流可能会导致非常大的缓冲区溢出。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-55629 | 7.5 HIGH | Suricata generic detection bypass using TCP urgent support |
| CVE-2024-55628 | 7.5 HIGH | Suricata oversized resource names utilizing DNS name compression can lead to resource star |
| CVE-2024-55605 | 7.5 HIGH | Suricata allows stack overflow in transforms |
| CVE-2024-55626 | 3.3 LOW | Suricata oversized bpf file can lead to buffer overflow |
No comments yet