#VU102518 Stack-based buffer overflow in Suricata - CVE-2024-55605
Published: January 10, 2025
Suricata
Open Information Security Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in multiple transforms. A remote attacker can send very large packets to the application, trigger a stack-based buffer overflow and perform a denial of service (DoS) attack.
Below is the list of affected transforms:
- to_lowercase
- to_uppercase
- strip_whitespace
- compress_whitespace
- dotprefix
- header_lowercase
- strip_pseudo_headers
- url_decode
- xor