Suricata是Open Information Security基金会的一个网络IDS、IPS和NSM引擎。 Suricata 7.0.8之前版本存在安全漏洞,该漏洞源于带有 TCP 紧急数据(带外数据)的 TCP 流可能会导致 Suricata 分析数据的方式与 TCP 端点的应用程序不同。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-55628 | 7.5 HIGH | Suricata oversized resource names utilizing DNS name compression can lead to resource star |
| CVE-2024-55605 | 7.5 HIGH | Suricata allows stack overflow in transforms |
| CVE-2024-55627 | 5.9 MEDIUM | Suricata segfault on StreamingBufferSlideToOffsetWithRegions |
| CVE-2024-55626 | 3.3 LOW | Suricata oversized bpf file can lead to buffer overflow |
No comments yet