Debian Security Advisory DSA-3254-1 [email protected]
http://www.debian.org/security/ Salvatore Bonaccorso
May 09, 2015 http://www.debian.org/security/faq
Package : suricata
CVE ID : CVE-2015-0971
Kostya Kortchinsky of the Google Security Team discovered a flaw in the
DER parser used to decode SSL/TLS certificates in suricata. A remote
attacker can take advantage of this flaw to cause suricata to crash.
For the stable distribution (jessie), this problem has been fixed in
version 2.0.7-2+deb8u1.
For the unstable distribution (sid), this problem has been fixed in
version 2.0.8-1.
We recommend that you upgrade your suricata packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: [email protected]
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 8 | armhf | suricata | < 2.0.7-2+deb8u1 | suricata_2.0.7-2+deb8u1_armhf.deb |
Debian | 8 | ppc64el | suricata | < 2.0.7-2+deb8u1 | suricata_2.0.7-2+deb8u1_ppc64el.deb |
Debian | 8 | i386 | suricata | < 2.0.7-2+deb8u1 | suricata_2.0.7-2+deb8u1_i386.deb |
Debian | 8 | mipsel | suricata | < 2.0.7-2+deb8u1 | suricata_2.0.7-2+deb8u1_mipsel.deb |
Debian | 8 | powerpc | suricata | < 2.0.7-2+deb8u1 | suricata_2.0.7-2+deb8u1_powerpc.deb |
Debian | 8 | armel | suricata | < 2.0.7-2+deb8u1 | suricata_2.0.7-2+deb8u1_armel.deb |
Debian | 8 | amd64 | suricata | < 2.0.7-2+deb8u1 | suricata_2.0.7-2+deb8u1_amd64.deb |
Debian | 8 | s390x | suricata | < 2.0.7-2+deb8u1 | suricata_2.0.7-2+deb8u1_s390x.deb |
Debian | 8 | all | suricata | < 2.0.7-2+deb8u1 | suricata_2.0.7-2+deb8u1_all.deb |
Debian | 8 | mips | suricata | < 2.0.7-2+deb8u1 | suricata_2.0.7-2+deb8u1_mips.deb |