CVE-2024-55605: Suricata allows stack overflow in transforms
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large input buffer to the tolowercase, touppercase, stripwhitespace, compresswhitespace, dotprefix, headerlowercase, strippseudoheaders, urldecode, or xor transform can lead to a stack overflow causing Suricata to crash. The issue has been addressed in Suricata 7.0.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55605?
CVE-2024-55605 has a moderate severity level due to potential denial of service risks.
How do I fix CVE-2024-55605?
To mitigate CVE-2024-55605, upgrade Suricata to version 7.0.8 or later.
What causes CVE-2024-55605?
CVE-2024-55605 is caused by a large input buffer being processed by various string manipulation functions.
Which versions of Suricata are affected by CVE-2024-55605?
Suricata versions prior to 7.0.8 are vulnerable to CVE-2024-55605.
What is the impact of CVE-2024-55605 on network security?
CVE-2024-55605 can lead to service disruption and denial of service, affecting network security monitoring.