Project

General

Profile

Actions

Security #6118

closed

datasets: absolute path in rules can overwrite arbitrary files

Added by Victor Julien over 1 year ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Label:
Git IDs:

fd79b337ca4618d9cf2ac7b37db98f81d97ffab2

Severity:
HIGH
Disclosure Date:

Description

Only restricted by permissions the Suricata process user & group, if any.


Subtasks 1 (0 open1 closed)

Security #6119: datasets: absolute path in rules can overwrite arbitrary files (6.0.x backport)ClosedJason IshActions
Actions #1

Updated by OISF Ticketbot over 1 year ago

  • Subtask #6119 added
Actions #2

Updated by OISF Ticketbot over 1 year ago

  • Label deleted (Needs backport to 6.0)
Actions #3

Updated by Jason Ish over 1 year ago

  • Severity changed from MODERATE to HIGH
Actions #4

Updated by Jason Ish over 1 year ago

  • Assignee changed from Eric Leblond to Jason Ish
Actions #5

Updated by Victor Julien over 1 year ago

  • Status changed from In Review to Resolved
Actions #6

Updated by Jason Ish over 1 year ago

  • Git IDs updated (diff)
Actions #7

Updated by Jason Ish over 1 year ago

  • Status changed from Resolved to Closed
Actions #8

Updated by Jason Ish over 1 year ago

  • CVE set to 2023-35852
Actions #9

Updated by Victor Julien over 1 year ago

  • Private changed from Yes to No
Actions

Also available in: Atom PDF