Lucene search

K
rosalinuxROSA LABROSA-SA-2023-2305
HistoryDec 12, 2023 - 12:21 p.m.

Advisory ROSA-SA-2023-2305

2023-12-1212:21:49
ROSA LAB
abf.rosalinux.ru
12
suricata 6.0.13
rosa-chrome
path restriction
arbitrary files
remote code execution
vulnerability fixes
input validation

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.9%

software: suricata 6.0.13
WASP: ROSA-CHROME

package_evr_string: suricata-6.0.13-1.src.rpm

CVE-ID: CVE-2023-35852
BDU-ID: 2023-06800
CVE-Crit: HIGH
CVE-DESC.: A vulnerability in the Suricata Intrusion Detection and Prevention System is related to an incorrect restriction of the path name of a restricted directory. Exploitation of the vulnerability could allow an intruder acting remotely to write arbitrary files to the file system
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update suricata

CVE-ID: CVE-2023-35853
BDU-ID: 2023-06802
CVE-Crit: CRITICAL.
CVE-DESC.: A vulnerability in Suricata’s intrusion detection and prevention system is related to insufficient input validation. Exploitation of the vulnerability could allow an intruder acting remotely to execute arbitrary code
CVE-STATUS: Resolved
CVE-REV: To close, run the command: sudo dnf update suricata

OSVersionArchitecturePackageVersionFilename
ROSAanynoarchsuricata< 6.0.13UNKNOWN

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.9%