We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-45796

Suricata defrag: off by one can lead to policy bypass



Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, a logic error during fragment reassembly can lead to failed reassembly for valid traffic. An attacker could craft packets to trigger this behavior.This issue has been addressed in 7.0.7.

Reserved 2024-09-09 | Published 2024-10-16 | Updated 2024-10-17 | Assigner GitHub_M


MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-193: Off-by-one Error

Product status

< 7.0.7
affected

References

github.com/...ricata/security/advisories/GHSA-mf6r-3xp2-v7xg

redmine.openinfosecfoundation.org/issues/7067

cve.org (CVE-2024-45796)

nvd.nist.gov (CVE-2024-45796)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-45796

Support options

Helpdesk Chat, Email, Knowledgebase