CVE-2018-10243
https://notcve.org/view.php?id=CVE-2018-10243
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header. htp_parse_authorization_digest en htp_parsers.c en LibHTP 0.5.26 permite a los atacantes remotos provocar una sobrelectura de búfer basada en memoria dinámica (heap) a través de una cabecera "authorization digest". • https://lists.debian.org/debian-lts-announce/2019/04/msg00010.html https://suricata-ids.org/2018/07/18/suricata-4-0-5-available • CWE-125: Out-of-bounds Read •
CVE-2018-1000167
https://notcve.org/view.php?id=CVE-2018-1000167
OISF suricata-update version 1.0.0a1 contains an Insecure Deserialization vulnerability in the insecure yaml.load-Function as used in the following files: config.py:136, config.py:142, sources.py:99 and sources.py:131. The "list-sources"-command is affected by this bug. that can result in Remote Code Execution(even as root if suricata-update is called by root). This attack appears to be exploitable via a specially crafted yaml-file at https://www.openinfosecfoundation.org/rules/index.yaml. This vulnerability appears to have been fixed in 1.0.0b1. OISF suricata-update 1.0.0a1 contiene una vulnerabilidad de deserialización no segura en la función insegura yaml.load, tal y como se emplea en los siguientes archivos: config.py:136, config.py:142, sources.py:99 y sources.py:131. • https://redmine.openinfosecfoundation.org/issues/2359 https://tech.feedyourhead.at/content/remote-code-execution-in-suricata-update • CWE-502: Deserialization of Untrusted Data •
CVE-2015-0928
https://notcve.org/view.php?id=CVE-2015-0928
libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference). libhtp 0.5.15 permite que los atacantes remotos provoquen una denegación de servicio (desreferencia de puntero NULL). • http://www.securityfocus.com/bid/73117 https://redmine.openinfosecfoundation.org/issues/1272 • CWE-476: NULL Pointer Dereference •