CVE-2024-32867

Name
CVE-2024-32867
Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of fragmentation anomalies can lead to mis-detection of rules and policy. This vulnerability is fixed in 7.0.5 or 6.0.19.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/OISF/suricata/commit/1e110d0a71db46571040b937e17a4bc9f91d6de9
security-advisories@github.com https://github.com/OISF/suricata/commit/2f39ba75f153ba9bdf8eedc2a839cc973dbaea66
security-advisories@github.com https://github.com/OISF/suricata/commit/414f97c6695c5a2e1d378a36a6f50d7288767634
security-advisories@github.com https://github.com/OISF/suricata/commit/bf3d420fb709ebe074019a99e3bd3a2364524a4b
security-advisories@github.com https://github.com/OISF/suricata/commit/d13bd2ae217a6d2ceb347f74d27cbfcd37b9bda9
security-advisories@github.com https://github.com/OISF/suricata/commit/e6267758ed5da27f804f0c1c07f9423bdf4d72b8
security-advisories@github.com https://github.com/OISF/suricata/security/advisories/GHSA-xvrx-88mv-xcq5
security-advisories@github.com https://redmine.openinfosecfoundation.org/issues/6672
security-advisories@github.com https://redmine.openinfosecfoundation.org/issues/6673
security-advisories@github.com https://redmine.openinfosecfoundation.org/issues/6677

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* suricata >= 6.0.0 < 6.0.19
cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:* suricata >= 7.0.0 < 7.0.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
suricata edge-community 7.0.6-r0 Steve McMaster <code@mcmaster.io> fixed
suricata edge-community 6.0.4-r0 Steve McMaster <code@mcmaster.io> possibly vulnerable
suricata edge-community 6.0.3-r0 Steve McMaster <code@mcmaster.io> possibly vulnerable
suricata 3.22-community 7.0.6-r0 None fixed
suricata 3.22-community 6.0.4-r0 None possibly vulnerable
suricata 3.22-community 6.0.3-r0 None possibly vulnerable
suricata 3.21-community 7.0.6-r0 None fixed
suricata 3.20-community 7.0.6-r0 Steve McMaster <code@mcmaster.io> fixed
suricata 3.20-community 6.0.7-r0 None fixed