CVE-2024-47187

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-47187
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-47187.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-47187
Aliases
  • GHSA-64ww-4f6x-863p
Related
Published
2024-10-16T19:15:27Z
Modified
2024-10-22T23:50:55.699724Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to datasets having predictable hash table behavior. This can lead to dataset file loading to use excessive time to load, as well as runtime performance issues during traffic handling. This issue has been addressed in 7.0.7. As a workaround, avoid loading datasets from untrusted sources. Avoid dataset rules that track traffic in rules.

References

Affected packages

Debian:11 / suricata

Package

Name
suricata
Purl
pkg:deb/debian/suricata?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:6.*

1:6.0.1-3
1:6.0.2-1~exp1
1:6.0.3-1~exp1
1:6.0.3-1~exp2
1:6.0.3-1
1:6.0.3-2~bpo11+1
1:6.0.3-2
1:6.0.4-1
1:6.0.4-2~bpo10+1
1:6.0.4-2~bpo11+1
1:6.0.4-2
1:6.0.4-3
1:6.0.5-1
1:6.0.5-2~bpo10+1
1:6.0.5-2~bpo11+1
1:6.0.5-2
1:6.0.5-3
1:6.0.6-1~bpo10+1
1:6.0.6-1~bpo11+1
1:6.0.6-1
1:6.0.6-2
1:6.0.8-1~bpo11+1
1:6.0.8-1
1:6.0.9-1~bpo11+1
1:6.0.9-1
1:6.0.10-1~bpo11+1
1:6.0.10-1
1:6.0.13-1

1:7.*

1:7.0.0-1
1:7.0.0-2~bpo12+1
1:7.0.0-2
1:7.0.1-1
1:7.0.2-1~bpo12+1
1:7.0.2-1
1:7.0.2-2~exp1
1:7.0.2-2~exp2
1:7.0.2-2
1:7.0.3-1~bpo12+1
1:7.0.3-1
1:7.0.4-1
1:7.0.5-1
1:7.0.5-2~bpo12+1
1:7.0.6-1~bpo12+1
1:7.0.6-1
1:7.0.6-2~exp1
1:7.0.7-1~bpo12+1
1:7.0.7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / suricata

Package

Name
suricata
Purl
pkg:deb/debian/suricata?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:6.*

1:6.0.10-1
1:6.0.13-1

1:7.*

1:7.0.0-1
1:7.0.0-2~bpo12+1
1:7.0.0-2
1:7.0.1-1
1:7.0.2-1~bpo12+1
1:7.0.2-1
1:7.0.2-2~exp1
1:7.0.2-2~exp2
1:7.0.2-2
1:7.0.3-1~bpo12+1
1:7.0.3-1
1:7.0.4-1
1:7.0.5-1
1:7.0.5-2~bpo12+1
1:7.0.6-1~bpo12+1
1:7.0.6-1
1:7.0.6-2~exp1
1:7.0.7-1~bpo12+1
1:7.0.7-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / suricata

Package

Name
suricata
Purl
pkg:deb/debian/suricata?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:7.0.7-1

Affected versions

1:6.*

1:6.0.10-1
1:6.0.13-1

1:7.*

1:7.0.0-1
1:7.0.0-2~bpo12+1
1:7.0.0-2
1:7.0.1-1
1:7.0.2-1~bpo12+1
1:7.0.2-1
1:7.0.2-2~exp1
1:7.0.2-2~exp2
1:7.0.2-2
1:7.0.3-1~bpo12+1
1:7.0.3-1
1:7.0.4-1
1:7.0.5-1
1:7.0.5-2~bpo12+1
1:7.0.6-1~bpo12+1
1:7.0.6-1
1:7.0.6-2~exp1
1:7.0.7-1~bpo12+1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/oisf/suricata

Affected ranges

Type
GIT
Repo
https://github.com/oisf/suricata
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

suricata-0.*

suricata-0.8.2

suricata-1.*

suricata-1.0.0
suricata-1.0.1
suricata-1.0.2
suricata-1.1
suricata-1.1beta1
suricata-1.1beta2
suricata-1.1beta3
suricata-1.1rc1
suricata-1.2
suricata-1.2.1
suricata-1.2beta1
suricata-1.2rc1
suricata-1.3
suricata-1.3.1
suricata-1.3beta1
suricata-1.3beta2
suricata-1.3rc1
suricata-1.4
suricata-1.4beta1
suricata-1.4beta2
suricata-1.4beta3
suricata-1.4rc1

suricata-2.*

suricata-2.0
suricata-2.0.1
suricata-2.0.1rc1
suricata-2.0.2
suricata-2.0beta1
suricata-2.0beta2
suricata-2.0rc1
suricata-2.0rc2
suricata-2.0rc3
suricata-2.1beta1
suricata-2.1beta2
suricata-2.1beta3
suricata-2.1beta4

suricata-3.*

suricata-3.0
suricata-3.0.1
suricata-3.0.1RC1
suricata-3.0RC1
suricata-3.0RC2
suricata-3.0RC3
suricata-3.1
suricata-3.1.1
suricata-3.1.2
suricata-3.1RC1
suricata-3.2
suricata-3.2.1
suricata-3.2RC1
suricata-3.2beta1

suricata-4.*

suricata-4.0.0
suricata-4.0.0-beta1
suricata-4.0.0-rc1
suricata-4.0.0-rc2
suricata-4.0.1
suricata-4.1.0
suricata-4.1.0-beta1
suricata-4.1.0-rc1
suricata-4.1.0-rc2
suricata-4.1.1
suricata-4.1.2

suricata-5.*

suricata-5.0.0
suricata-5.0.0-beta1
suricata-5.0.0-rc1
suricata-5.0.1

suricata-6.*

suricata-6.0.0
suricata-6.0.0-beta1
suricata-6.0.0-rc1
suricata-6.0.1

suricata-7.*

suricata-7.0.0
suricata-7.0.0-beta1
suricata-7.0.0-rc1
suricata-7.0.0-rc2
suricata-7.0.1
suricata-7.0.2
suricata-7.0.3
suricata-7.0.4
suricata-7.0.5
suricata-7.0.6