Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jason Ish

#35694of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2024-32468
7.5
2024-10-16
Suricata · Suricata · CVE-2024-47187
**Name of the Vulnerable Software and Affected Versions** Suricata versions prior to 7.0.7 **Description** Suricata is a network Intrusion Detection System, Intrusion Prevention System, and Network Security Monitoring engine. The issue arises from the missing initialization of the random seed for `thash`, leading to datasets having predictable hash table behavior. This results in dataset file loading taking excessive time and runtime performance issues during traffic handling. **Recommendations** For versions prior to 7.0.7, update to version 7.0.7 to address the issue. As a temporary workaround, avoid loading datasets from untrusted sources. Avoid using dataset rules that track traffic in rules to minimize the risk of exploitation.