CVE-2024-45795

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, rules using datasets with the non-functional / unimplemented "unset" option can trigger an assertion during traffic parsing, leading to denial of service. This issue is addressed in 7.0.7. As a workaround, use only trusted and well tested rulesets.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

History

22 Oct 2024, 13:35

Type Values Removed Values Added
References () https://github.com/OISF/suricata/security/advisories/GHSA-6r8w-fpw6-cp9g - () https://github.com/OISF/suricata/security/advisories/GHSA-6r8w-fpw6-cp9g - Third Party Advisory
References () https://redmine.openinfosecfoundation.org/issues/7195 - () https://redmine.openinfosecfoundation.org/issues/7195 - Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
First Time Oisf suricata
Oisf

18 Oct 2024, 12:53

Type Values Removed Values Added
Summary
  • (es) Suricata es un sistema de detección de intrusiones, un sistema de prevención de intrusiones y un motor de monitoreo de seguridad de red. Antes de la versión 7.0.7, las reglas que utilizan conjuntos de datos con la opción "unset" no funcional o no implementada pueden activar una aserción durante el análisis del tráfico, lo que genera una denegación de servicio. Este problema se soluciona en la versión 7.0.7. Como workaround, utilice solo conjuntos de reglas confiables y bien probados.

16 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-16 19:15

Updated : 2024-10-22 13:35


NVD link : CVE-2024-45795

Mitre link : CVE-2024-45795

CVE.ORG link : CVE-2024-45795


JSON object : View

Products Affected

oisf

  • suricata
CWE
CWE-617

Reachable Assertion