Bug 13578

Summary: [CVE 21] suricata 6.0.12 CVEs found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: RESOLVED FIXED QA Contact: ROSA Linux Bugs <bugs>
Severity: normal    
Priority: Normal CC: a.proklov, e.kosachev, i.gaptrakhmanov, pastordidi, s.matveev, v.potapov, y.tumanov
Version: AllFlags: v.potapov: qa_verified+
y.tumanov: secteam_verified+
a.proklov: published+
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: CVE-2023-35852, CVE-2023-35853,
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Yury 2023-08-24 00:23:12 MSK
Please patch CVEs for package suricata version 6.0.12
  
INFO (CVEs are): suricata 6.0.12
 cves found
CVE-2023-35852
Desc: In Suricata before 6.0.13 (when there is an adversary who controls an external source of rules), a dataset filename, that comes from a rule, may trigger absolute or relative directory traversal, and lead to write access to a local filesystem. This is addressed in 6.0.13 by requiring allow-absolute-filenames and allow-write (in the datasets rules configuration section) if an installation requires traversal/writing in this situation.
Link: https://nvd.nist.gov/vuln/detail/CVE-2023-35852
Severity: HIGH
CVE-2023-35853
Desc: In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.
Link: https://nvd.nist.gov/vuln/detail/CVE-2023-35853
Severity: CRITICAL
Comment 1 ilfat 2023-08-31 16:32:09 MSK
********** QA ADVISORY **********

CVEs closed by project update:

Updated to 6.0.13

https://abf.io/build_lists/4676881 x86_64
https://abf.io/build_lists/4676880 i686
https://abf.io/build_lists/4676882 aarch64
Comment 2 Dmitry Postnikov 2023-09-04 10:47:58 MSK
****************************
The update sent to testings
Comment 3 Vladimir Potapov 2023-09-12 08:55:12 MSK
suricata-6.0.13-1
https://abf.io/build_lists/4676881 x86_64
https://abf.io/build_lists/4676880 i686
https://abf.io/build_lists/4676882 aarch64
************************** Advisory **********************
CVEs closed by project update:
Updated to 6.0.13
**********************************************************
QA Verified
Comment 4 Yury 2023-10-19 13:04:56 MSK
secteam_verified