OISF Suricata
cpe:2.3:a:openinfosecfoundation:suricata:*:*:*:*:*:*:*
- < 7.0.8
A buffer overflow vulnerability has been identified in Suricata versions prior to 7.0.8. This issue arises from an unsigned integer underflow, which allows a specially crafted TCP stream to cause a significant buffer overflow. The vulnerability occurs because the buffer is initialized with zeroes using memset, creating an opportunity for the overflow to be exploited.
Exploitation of this vulnerability leads to a large buffer overflow, which can commonly result in arbitrary code execution or causing a segmentation fault, depending on the context.
The vulnerability can be reproduced by sending a specially crafted TCP stream to the Suricata application. This stream should be designed to exploit the unsigned integer underflow in the streaming buffer management, causing a buffer overflow when the data is processed.
Users can upgrade to Suricata version 7.0.8 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.