Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to byte-range tracking having predictable hash table behavior. This can lead to an attacker forcing lots of data into a single hash bucket, leading to severe performance degradation. This issue has been addressed in 7.0.7.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
The product uses a broken or risky cryptographic algorithm or protocol.
Link | Tags |
---|---|
https://github.com/OISF/suricata/security/advisories/GHSA-qq5v-qcjx-f872 | third party advisory |
https://redmine.openinfosecfoundation.org/issues/7289 | issue tracking |