Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-35852
HistoryJun 19, 2023 - 12:00 a.m.

CVE-2023-35852

2023-06-1900:00:00
ubuntu.com
ubuntu.com
13
suricata
6.0.13
directory traversal
absolute filenames
write access
datasets
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

43.3%

In Suricata before 6.0.13 (when there is an adversary who controls an
external source of rules), a dataset filename, that comes from a rule, may
trigger absolute or relative directory traversal, and lead to write access
to a local filesystem. This is addressed in 6.0.13 by requiring
allow-absolute-filenames and allow-write (in the datasets rules
configuration section) if an installation requires traversal/writing in
this situation.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

43.3%