-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

5B-------------------------------------------------------------------------
Debian Security Advisory DSA-6475-1                   [email protected]
https://www.debian.org/security/                       Moritz Muehlenhoff
August 27, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : suricata-update
CVE ID         : CVE-2026-63347

Guillem Lefait discovered a path traversal attack in suricata-update,
a tool for updating Suricata rules, which allowed malformed rules to
overwrite files on the system.

For the stable distribution (trixie), this problem has been fixed in
version 1.3.4-1+deb13u1.

We recommend that you upgrade your suricata-update packages.

For the detailed security status of suricata-update please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/suricata-update

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqQV60ACgkQEMKTtsN8
TjaiOxAAvK9vFrwuRU5x5M2vxDvFB4DXPQVFCPKZSurbLGLiw8EI6GR65bGecftk
VeM+SKYCF8D4ZnnBS6dCl97F19G7GT6vmV7N9ME1ByN/kW036xMMYq/NNjtQXr7J
mdBwfT506nGoVsZar2Zd10PI4E71/YpwpG/Y0K9EwbuJ02D6by7oWR1ELB1WioMR
n0Uly0kS2WBEJYFflEUuQ9Cq4NAvc97FZ5COK0GsJNOFnYhOl36aMpC0O21dVNXU
+jXuUe9TEloWW0AZnk9p9EceBls/JgU35W2poByEBaWan+BBR45LxZIxowMWg6MT
HMB00KuJDtt0zCUo/Aj/L/eDIivmJ9JMWKL8V4nhvkn7mEZIHxK4KYSnF5sGH9C1
VlI4SmBDjn+6wk4sdjKnfvafjdogQOr0lJwMWZ3ZK2hfLHmQx67mN+js5je7uflz
YGCkr+qcjRzCmYTRCjwUdh8oqufulHX81Jpp0TiJ0YTENkdMPAweyaShfY3YSGGP
NS4v3CapCmurFK6K9FeXbumHvNZPHYXlmdfPB5qJEWbKSRs5uisHVvjfKIDwnl+B
aHfnX4O8I08MEMbn8AqSPufBC0cI8U0xt5epaCh9Ob990xTi3FYfyZM1ohKzu6sn
ADVjzXkLC/1QLqlydjunCmgug086FCd6eQvW6MCgtSBlwv2NNG4=
=PTAV
-----END PGP SIGNATURE-----

Reply via email to