oss-sec mailing list archives

CVE request: denial of service in suricata


From: Pierre Schweitzer <pierre () reactos org>
Date: Fri, 12 Dec 2014 13:56:13 +0100

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Dear all,

It appears, looking at bug #1272 [1] in Suricata, that it was possible
to crash Suricata with specific packets due to a bug in the libhtp
(which got fixed with libhtp 0.5.16).

It got fixed with the release 2.0.5 from Suricata.

Was a CVE already assigned to this issue? Otherwise can a CVE be assigned?

With my best regards,

[1]: https://redmine.openinfosecfoundation.org/issues/1272

- -- 
Pierre Schweitzer <pierre () reactos org>
System & Network Administrator
Senior Kernel Developer
ReactOS Deutschland e.V.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJUiuXtAAoJEHVFVWw9WFsL8a0QAKpH57yNCdnjHcHm3xxyNk5R
cwgMtmIBOqntLcK1NUg4pFXChIFFzH/4Alj/KyHFO8l3rHdgYyY1c3ZQJMirQ+dL
h6HIr2UJy6rM7H+n2Q1d1owonJWkSDZP8xygxwRDRBy6gvL5Bd5i2Kr0xttxvfz4
QN+HzeFvdo3DUO1lXhdBihDkhksYCaCJoO0zw2QKo6roLSLFTyqNXVZav9wza4Kq
0iNsrlV1hpRmYiSRMPvYrSwxqOWBTkZeXfS8QI+TCbVEFiHsOZtSFf8knIuvuFN+
+wsqpSkCpPXL3CTTAXwkjnn2iAmd82hI7OmhiCOkRSU/YQCeG/KZhUkGm8HjazcI
t4pJUe9VB233atkhQ7kqkM1pH1K6t7ssAALFMwxSyCgdYlU6WaTJy++NMCMoS3ZM
WSVzDATOEp+RATJt6FAvPvsLuVLZehUa/hRnjWN9rdB+e8tV7eeJ8oIUf8JrzesY
bU8vDGaIog8u8J9VJVjrgS6zZ9RLOAqFlc4fWTTe+6H727GOLuT/agkV2ulIOP07
JGfBIOKCFmJ5yVDSMYY0+2u6n+XoEiua03GcEbZzZb8NPA+8O1CUhqtRZadJtGLQ
57QXS91fq2/NGBqQz5Rm11E1VaPJBGSue1pKNY/shkLCnFMcUK6ww8YjhJl3HQc7
I+ANlGpK4EZZ3Ehq4/Nx
=w1nx
-----END PGP SIGNATURE-----


Current thread: