CVE-2024-32867

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of fragmentation anomalies can lead to mis-detection of rules and policy. This vulnerability is fixed in 7.0.5 or 6.0.19.
References
Link Resource
https://github.com/OISF/suricata/commit/1e110d0a71db46571040b937e17a4bc9f91d6de9 Patch
https://github.com/OISF/suricata/commit/2f39ba75f153ba9bdf8eedc2a839cc973dbaea66 Patch
https://github.com/OISF/suricata/commit/414f97c6695c5a2e1d378a36a6f50d7288767634 Patch
https://github.com/OISF/suricata/commit/bf3d420fb709ebe074019a99e3bd3a2364524a4b Patch
https://github.com/OISF/suricata/commit/d13bd2ae217a6d2ceb347f74d27cbfcd37b9bda9 Patch
https://github.com/OISF/suricata/commit/e6267758ed5da27f804f0c1c07f9423bdf4d72b8 Patch
https://github.com/OISF/suricata/security/advisories/GHSA-xvrx-88mv-xcq5 Vendor Advisory
https://redmine.openinfosecfoundation.org/issues/6672 Issue Tracking
https://redmine.openinfosecfoundation.org/issues/6673 Issue Tracking
https://redmine.openinfosecfoundation.org/issues/6677 Issue Tracking
https://github.com/OISF/suricata/commit/1e110d0a71db46571040b937e17a4bc9f91d6de9 Patch
https://github.com/OISF/suricata/commit/2f39ba75f153ba9bdf8eedc2a839cc973dbaea66 Patch
https://github.com/OISF/suricata/commit/414f97c6695c5a2e1d378a36a6f50d7288767634 Patch
https://github.com/OISF/suricata/commit/bf3d420fb709ebe074019a99e3bd3a2364524a4b Patch
https://github.com/OISF/suricata/commit/d13bd2ae217a6d2ceb347f74d27cbfcd37b9bda9 Patch
https://github.com/OISF/suricata/commit/e6267758ed5da27f804f0c1c07f9423bdf4d72b8 Patch
https://github.com/OISF/suricata/security/advisories/GHSA-xvrx-88mv-xcq5 Vendor Advisory
https://redmine.openinfosecfoundation.org/issues/6672 Issue Tracking
https://redmine.openinfosecfoundation.org/issues/6673 Issue Tracking
https://redmine.openinfosecfoundation.org/issues/6677 Issue Tracking
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

History

19 Dec 2024, 19:48

Type Values Removed Values Added
First Time Oisf suricata
Oisf
CPE cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
References () https://github.com/OISF/suricata/commit/1e110d0a71db46571040b937e17a4bc9f91d6de9 - () https://github.com/OISF/suricata/commit/1e110d0a71db46571040b937e17a4bc9f91d6de9 - Patch
References () https://github.com/OISF/suricata/commit/2f39ba75f153ba9bdf8eedc2a839cc973dbaea66 - () https://github.com/OISF/suricata/commit/2f39ba75f153ba9bdf8eedc2a839cc973dbaea66 - Patch
References () https://github.com/OISF/suricata/commit/414f97c6695c5a2e1d378a36a6f50d7288767634 - () https://github.com/OISF/suricata/commit/414f97c6695c5a2e1d378a36a6f50d7288767634 - Patch
References () https://github.com/OISF/suricata/commit/bf3d420fb709ebe074019a99e3bd3a2364524a4b - () https://github.com/OISF/suricata/commit/bf3d420fb709ebe074019a99e3bd3a2364524a4b - Patch
References () https://github.com/OISF/suricata/commit/d13bd2ae217a6d2ceb347f74d27cbfcd37b9bda9 - () https://github.com/OISF/suricata/commit/d13bd2ae217a6d2ceb347f74d27cbfcd37b9bda9 - Patch
References () https://github.com/OISF/suricata/commit/e6267758ed5da27f804f0c1c07f9423bdf4d72b8 - () https://github.com/OISF/suricata/commit/e6267758ed5da27f804f0c1c07f9423bdf4d72b8 - Patch
References () https://github.com/OISF/suricata/security/advisories/GHSA-xvrx-88mv-xcq5 - () https://github.com/OISF/suricata/security/advisories/GHSA-xvrx-88mv-xcq5 - Vendor Advisory
References () https://redmine.openinfosecfoundation.org/issues/6672 - () https://redmine.openinfosecfoundation.org/issues/6672 - Issue Tracking
References () https://redmine.openinfosecfoundation.org/issues/6673 - () https://redmine.openinfosecfoundation.org/issues/6673 - Issue Tracking
References () https://redmine.openinfosecfoundation.org/issues/6677 - () https://redmine.openinfosecfoundation.org/issues/6677 - Issue Tracking

21 Nov 2024, 09:15

Type Values Removed Values Added
Summary
  • (es) Suricata es un sistema de detección de intrusiones en la red, un sistema de prevención de intrusiones y un motor de monitoreo de seguridad de la red. Antes de 7.0.5 y 6.0.19, varios problemas en el manejo de anomalías de fragmentación pueden provocar una detección errónea de reglas y políticas. Esta vulnerabilidad se solucionó en 7.0.5 o 6.0.19.
References () https://github.com/OISF/suricata/commit/1e110d0a71db46571040b937e17a4bc9f91d6de9 - () https://github.com/OISF/suricata/commit/1e110d0a71db46571040b937e17a4bc9f91d6de9 -
References () https://github.com/OISF/suricata/commit/2f39ba75f153ba9bdf8eedc2a839cc973dbaea66 - () https://github.com/OISF/suricata/commit/2f39ba75f153ba9bdf8eedc2a839cc973dbaea66 -
References () https://github.com/OISF/suricata/commit/414f97c6695c5a2e1d378a36a6f50d7288767634 - () https://github.com/OISF/suricata/commit/414f97c6695c5a2e1d378a36a6f50d7288767634 -
References () https://github.com/OISF/suricata/commit/bf3d420fb709ebe074019a99e3bd3a2364524a4b - () https://github.com/OISF/suricata/commit/bf3d420fb709ebe074019a99e3bd3a2364524a4b -
References () https://github.com/OISF/suricata/commit/d13bd2ae217a6d2ceb347f74d27cbfcd37b9bda9 - () https://github.com/OISF/suricata/commit/d13bd2ae217a6d2ceb347f74d27cbfcd37b9bda9 -
References () https://github.com/OISF/suricata/commit/e6267758ed5da27f804f0c1c07f9423bdf4d72b8 - () https://github.com/OISF/suricata/commit/e6267758ed5da27f804f0c1c07f9423bdf4d72b8 -
References () https://github.com/OISF/suricata/security/advisories/GHSA-xvrx-88mv-xcq5 - () https://github.com/OISF/suricata/security/advisories/GHSA-xvrx-88mv-xcq5 -
References () https://redmine.openinfosecfoundation.org/issues/6672 - () https://redmine.openinfosecfoundation.org/issues/6672 -
References () https://redmine.openinfosecfoundation.org/issues/6673 - () https://redmine.openinfosecfoundation.org/issues/6673 -
References () https://redmine.openinfosecfoundation.org/issues/6677 - () https://redmine.openinfosecfoundation.org/issues/6677 -

07 May 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-07 15:15

Updated : 2024-12-19 19:48


NVD link : CVE-2024-32867

Mitre link : CVE-2024-32867

CVE.ORG link : CVE-2024-32867


JSON object : View

Products Affected

oisf

  • suricata
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions