Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 724536 - <net-analyzer/suricata-5.0.3: Multiple vulnerabilities
Summary: <net-analyzer/suricata-5.0.3: Multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://suricata-ids.org/2020/04/28/s...
Whiteboard: ~3 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-05-22 08:03 UTC by Sam James
Modified: 2020-05-23 03:05 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-22 08:03:30 UTC
"This is the first release after Suricata joined the Oss-Fuzz program, leading to discovery of a number of (potential) security issues. We expect that in the coming months we’ll fix more such issues, as the fuzzers increase their coverage and we continue to improve the seed corpus."

e.g.
Bug #3526: 5.0.x Kerberos vulnerable to TCP splitting evasion
Bug #3585: htp: asan issue
Bug #3592: Segfault on SMTP TLS
Bug #3665: FTP: Incorrect ftp_memuse calculation.
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-22 08:03:49 UTC
@maintainer(s), please bump to 5.0.3.
Comment 2 Larry the Git Cow gentoo-dev 2020-05-22 21:02:21 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=00b295187723410950b9e6fed2b221a68bdacb5b

commit 00b295187723410950b9e6fed2b221a68bdacb5b
Author:     Marek Szuba <marecki@gentoo.org>
AuthorDate: 2020-05-22 20:58:25 +0000
Commit:     Marek Szuba <marecki@gentoo.org>
CommitDate: 2020-05-22 21:01:55 +0000

    net-analyzer/suricata: bump to 5.0.3 + remove 5.0.2
    
    Bug: https://bugs.gentoo.org/724536
    Signed-off-by: Marek Szuba <marecki@gentoo.org>

 net-analyzer/suricata/Manifest                                         | 2 +-
 net-analyzer/suricata/{suricata-5.0.2.ebuild => suricata-5.0.3.ebuild} | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-05-23 03:05:27 UTC
Thank you! :)