7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): HIGH
Activity log
- Created suggestion
Suricata krb5: quadratic complexity in krb5 buffering
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 and 8.0.4.
References
-
https://github.com/OISF/suricata/security/advisories/GHSA-rp9m-jcpw-hggr x_refsource_CONFIRM
-
https://redmine.openinfosecfoundation.org/issues/8305 x_refsource_MISC
Affected products
- ==< 7.0.15
- ==>= 8.0.0, < 8.0.4
Package maintainers
-
@magenbluten magenbluten <magenbluten@codemonkey.cc>