CVE-2024-32867
published 2024-05-07CVE-2024-32867: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.70%
48.5th percentile
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of fragmentation anomalies can lead to mis-detection of rules and policy. This vulnerability is fixed in 7.0.5 or 6.0.19.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | suricata | < suricata 1:7.0.5-1 (forky) | suricata 1:7.0.5-1 (forky) |
| oisf | suricata | — | — |
| oisf | suricata | — | — |
| oisf | suricata | >= 0 < 1:7.0.5-1 | 1:7.0.5-1 |
| oisf | suricata | >= 0 < 1:7.0.5-1 | 1:7.0.5-1 |
| oisf | suricata | >= 6.0.0 < 6.0.19 | 6.0.19 |
| oisf | suricata | >= 7.0.0 < 7.0.5 | 7.0.5 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-32867: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
vendor_debian·2024·CVSS 5.3
CVE-2024-32867 [MEDIUM] CVE-2024-32867: suricata - Suricata is a network Intrusion Detection System, Intrusion Prevention System an...
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of fragmentation anomalies can lead to mis-detection of rules and policy. This vulnerability is fixed in 7.0.5 or 6.0.19.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:7.0.5-1)
sid: resolved (fixed in 1:7.0.5-1)
trixie: resolved (fixed in 1:7.0.5-1)
OSV
CVE-2024-32867: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine
osv·2024-05-07·CVSS 5.3
CVE-2024-32867 [MEDIUM] CVE-2024-32867: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of fragmentation anomalies can lead to mis-detection of rules and policy. This vulnerability is fixed in 7.0.5 or 6.0.19.
No detection rules found.
No public exploits indexed.
https://github.com/OISF/suricata/commit/1e110d0a71db46571040b937e17a4bc9f91d6de9https://github.com/OISF/suricata/commit/2f39ba75f153ba9bdf8eedc2a839cc973dbaea66https://github.com/OISF/suricata/commit/414f97c6695c5a2e1d378a36a6f50d7288767634https://github.com/OISF/suricata/commit/bf3d420fb709ebe074019a99e3bd3a2364524a4bhttps://github.com/OISF/suricata/commit/d13bd2ae217a6d2ceb347f74d27cbfcd37b9bda9https://github.com/OISF/suricata/commit/e6267758ed5da27f804f0c1c07f9423bdf4d72b8https://github.com/OISF/suricata/security/advisories/GHSA-xvrx-88mv-xcq5https://redmine.openinfosecfoundation.org/issues/6672https://redmine.openinfosecfoundation.org/issues/6673https://redmine.openinfosecfoundation.org/issues/6677https://github.com/OISF/suricata/commit/1e110d0a71db46571040b937e17a4bc9f91d6de9https://github.com/OISF/suricata/commit/2f39ba75f153ba9bdf8eedc2a839cc973dbaea66https://github.com/OISF/suricata/commit/414f97c6695c5a2e1d378a36a6f50d7288767634https://github.com/OISF/suricata/commit/bf3d420fb709ebe074019a99e3bd3a2364524a4bhttps://github.com/OISF/suricata/commit/d13bd2ae217a6d2ceb347f74d27cbfcd37b9bda9https://github.com/OISF/suricata/commit/e6267758ed5da27f804f0c1c07f9423bdf4d72b8https://github.com/OISF/suricata/security/advisories/GHSA-xvrx-88mv-xcq5https://redmine.openinfosecfoundation.org/issues/6672https://redmine.openinfosecfoundation.org/issues/6673https://redmine.openinfosecfoundation.org/issues/6677
2024-05-07
Published