Suricata update 7.0.3 and 6.0.16 addressing critical vulnerabilities.

The OISF (Open Information Security Foundation) has released corrective updates for the Suricata intrusion detection and prevention system, versions 7.0.3 and 6.0.16, addressing five vulnerabilities, three of which (CVE-2024-23839, CVE-2024-23836, CVE-2024-23837) are classified as critical. The descriptions of the vulnerabilities have not been disclosed yet; however, a critical classification is typically assigned when there is a potential for remote code execution by an attacker. All Suricata users are urged to urgently update their systems.

The changelog for Suricata does not explicitly highlight the vulnerabilities, but one of the fixes notes an issue with memory access after it has been freed while processing malformed HTTP headers. One of the critical vulnerabilities (CVE-2024-23837) exists in the HTTP traffic parsing library LibHTP.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster