Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.response_header keyword. The vulnerability has been patched in 7.0.3. To work around the vulnerability, avoid the http.request_header and http.response_header keywords.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-21280 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.response_header keyword. The vulnerability has been patched in 7.0.3. To work around the vulnerability, avoid the http.request_header and http.response_header keywords. |
References
History
Thu, 19 Dec 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedoraproject
Fedoraproject fedora Oisf Oisf suricata |
|
| CPEs | cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fedoraproject
Fedoraproject fedora Oisf Oisf suricata |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:39:56.397Z
Reserved: 2024-01-22T22:23:54.342Z
Link: CVE-2024-23839
Updated: 2024-08-01T23:13:08.247Z
Status : Analyzed
Published: 2024-02-26T16:27:58.090
Modified: 2024-12-19T19:38:28.107
Link: CVE-2024-23839
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD