Bugtraq mailing list archives
[SECURITY] [DSA 3254-1] suricata security update
From: Salvatore Bonaccorso <carnil () debian org>
Date: Sat, 09 May 2015 14:44:51 +0000
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3254-1 security () debian org http://www.debian.org/security/ Salvatore Bonaccorso May 09, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : suricata CVE ID : CVE-2015-0971 Kostya Kortchinsky of the Google Security Team discovered a flaw in the DER parser used to decode SSL/TLS certificates in suricata. A remote attacker can take advantage of this flaw to cause suricata to crash. For the stable distribution (jessie), this problem has been fixed in version 2.0.7-2+deb8u1. For the unstable distribution (sid), this problem has been fixed in version 2.0.8-1. We recommend that you upgrade your suricata packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce () lists debian org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJVThyLAAoJEAVMuPMTQ89E4BgP/34wihdTIJoUGG6prBqmxbp9 RqsxFNdd+RA39wPRE1jV5EegaLjQIxAsosOuEsyYdWv+ejqg1wtRYtqwd+r9UiE2 aXO004SnhJ5UVLW35JMrFrltRRyh1noEtzzOUYn6XZPAoj02w9RRAIuDzlmvvWW6 2i2aVxOGpous6XlOnLtnwObUmaSctJn6EzLid1PLn8SmH3p4T8iaFPJ8uRJ69ZdY /r8ocyiTLBeGuceUr1LKQ3ebiE2CGSTGXTnFtsA3Jw/stdHjYH+TyqdNOYxQ56Ge xIen7pAO4L8lV1YV5ZKEtCNJ+3WXDwmPLaOM8RrnhfPDk17BY7VKwKMU8A/3CIkr Bv9k1TI2xsTeQPfoNxg2H8IDwxbwk3XuZI4QQNCOmYZ6jWThrUwgXQLozF9t3FeN NIdXalLArD+e0iD1GVisMlKOz8DWQvidkoCWKHatkjdxOKYSpiS6KFLUMRwMCiuv WlAjwYlCmNVbNjHiBdDckNcxPE0DPl3Rsj2S1wd5LstYR5DZO4UyZm0Ot2FB1+/3 NS8Ual7ksA4F4snw7pZ+BfCsIJpECtHEuyN6imSd8YNuVQrgQacDaDR/lUGlc6sV UAIhuvkOQWvj9acnDoIBrxKFBg1njy1S3W+0RcQ2hWhEn6RV1VBNGs5zEzb8qb2x IXFwTBInH43gTtSs1l/l =A+CU -----END PGP SIGNATURE-----
Current thread:
- [SECURITY] [DSA 3254-1] suricata security update Salvatore Bonaccorso (May 11)