Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-23839
HistoryFeb 26, 2024 - 12:00 a.m.

CVE-2024-23839

2024-02-2600:00:00
ubuntu.com
ubuntu.com
4
suricata
network security
intrusion detection system
prevention system
monitoring engine
cve-2024-23839
heap use after free
patched
http headers

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

AI Score

7

Confidence

High

EPSS

0

Percentile

15.5%

Suricata is a network Intrusion Detection System, Intrusion Prevention
System and Network Security Monitoring engine. Prior to 7.0.3, specially
crafted traffic can cause a heap use after free if the ruleset uses the
http.request_header or http.response_header keyword. The vulnerability has
been patched in 7.0.3. To work around the vulnerability, avoid the
http.request_header and http.response_header keywords.

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

AI Score

7

Confidence

High

EPSS

0

Percentile

15.5%