PT-2025-48204 · Open Information Security Foundation+2 · Suricata+2
CVE-2025-64331
·
Publicado
2025-11-06
·
Atualizado
2026-01-22
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Suricata versions prior to 7.0.13
Suricata versions prior to 8.0.2
Description
Suricata is a network IDS, IPS and NSM engine. A stack overflow can occur during large HTTP file transfers if the HTTP response body limit is increased and logging of printable HTTP bodies is enabled. The issue has been addressed in newer versions. A workaround involves using default HTTP response body limits and/or disabling http-body-printable logging, which is disabled by default.
Recommendations
Update to Suricata version 7.0.13 or later.
Update to Suricata version 8.0.2 or later.
Use default HTTP response body limits.
Disable http-body-printable logging.
Exploit
Correção
Memory Corruption
Stack Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Debian
Suricata