PT-2026-95644 · Suricata · Suricata
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Suricata versions prior to 7.0.17
Suricata versions prior to 8.0.6
Description
HTTP SWF decompression, when using the non-default
swf-decompression feature and an unsafe decompress-depth, may use the configured depth for allocation in src/util-file-decompression.c instead of limiting it to the actual data requirement of the Flash file. A specially crafted SWF response can trigger an integer-related heap buffer overflow, leading to a crash of the system. The default disabled state of the feature and the default depth are not affected.Recommendations
Update to version 7.0.17 or later.
Update to version 8.0.6 or later.
As a temporary mitigation, disable the
swf-decompression feature.Exploit
Fix
DoS
Integer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suricata