CVE-2024-55629

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, TCP streams with TCP urgent data (out of band data) can lead to Suricata analyzing data differently than the applications at the TCP endpoints, leading to possible evasions. Suricata 7.0.8 includes options to allow users to configure how to handle TCP urgent data. In IPS mode, you can use a rule such as drop tcp any any -> any any (sid:1; tcp.flags:U*;) to drop all the packets with urgent flag set.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

History

31 Mar 2025, 12:54

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*
CWE CWE-436
First Time Oisf suricata
Oisf
References () https://github.com/OISF/suricata/commit/6882bcb3e51bd3cf509fb6569cc30f48d7bb53d7 - () https://github.com/OISF/suricata/commit/6882bcb3e51bd3cf509fb6569cc30f48d7bb53d7 - Patch
References () https://redmine.openinfosecfoundation.org/issues/7411 - () https://redmine.openinfosecfoundation.org/issues/7411 - Permissions Required
References () https://github.com/OISF/suricata/commit/779f9d8ba35c3f9b5abfa327d3a4209861bd2eb8 - () https://github.com/OISF/suricata/commit/779f9d8ba35c3f9b5abfa327d3a4209861bd2eb8 - Patch
References () https://github.com/OISF/suricata/security/advisories/GHSA-69wr-vhwg-84h2 - () https://github.com/OISF/suricata/security/advisories/GHSA-69wr-vhwg-84h2 - Vendor Advisory

06 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-06 18:15

Updated : 2025-03-31 12:54


NVD link : CVE-2024-55629

Mitre link : CVE-2024-55629


JSON object : View

Products Affected

oisf

  • suricata
CWE
CWE-436

Interpretation Conflict

CWE-437

Incomplete Model of Endpoint Features