CVE-2024-38536

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A memory allocation failure due to `http.memcap` being reached leads to a NULL-ptr reference leading to a crash. Upgrade to 7.0.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

History

12 Jul 2024, 18:45

Type Values Removed Values Added
Summary
  • (es) Suricata es un sistema de detección de intrusiones en la red, un sistema de prevención de intrusiones y un motor de monitoreo de seguridad de la red. un fallo en la asignación de memoria debido a que se alcanzó `http.memcap` genera una referencia NULL-ptr que provoca un bloqueo. Actualice a 7.0.6.
First Time Oisf suricata
Oisf
References () https://github.com/OISF/suricata/security/advisories/GHSA-j32j-4w6g-94hh - () https://github.com/OISF/suricata/security/advisories/GHSA-j32j-4w6g-94hh - Vendor Advisory
References () https://redmine.openinfosecfoundation.org/issues/7029 - () https://redmine.openinfosecfoundation.org/issues/7029 - Exploit, Issue Tracking
References () https://redmine.openinfosecfoundation.org/issues/7033 - () https://redmine.openinfosecfoundation.org/issues/7033 - Issue Tracking
CPE cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

11 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-11 15:15

Updated : 2024-07-12 18:45


NVD link : CVE-2024-38536

Mitre link : CVE-2024-38536

CVE.ORG link : CVE-2024-38536


JSON object : View

Products Affected

oisf

  • suricata
CWE
CWE-476

NULL Pointer Dereference