-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 5B------------------------------------------------------------------------- Debian Security Advisory DSA-6475-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff August 27, 2026 https://www.debian.org/security/faq - -------------------------------------------------------------------------
Package : suricata-update CVE ID : CVE-2026-63347 Guillem Lefait discovered a path traversal attack in suricata-update, a tool for updating Suricata rules, which allowed malformed rules to overwrite files on the system. For the stable distribution (trixie), this problem has been fixed in version 1.3.4-1+deb13u1. We recommend that you upgrade your suricata-update packages. For the detailed security status of suricata-update please refer to its security tracker page at: https://security-tracker.debian.org/tracker/suricata-update Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqQV60ACgkQEMKTtsN8 TjaiOxAAvK9vFrwuRU5x5M2vxDvFB4DXPQVFCPKZSurbLGLiw8EI6GR65bGecftk VeM+SKYCF8D4ZnnBS6dCl97F19G7GT6vmV7N9ME1ByN/kW036xMMYq/NNjtQXr7J mdBwfT506nGoVsZar2Zd10PI4E71/YpwpG/Y0K9EwbuJ02D6by7oWR1ELB1WioMR n0Uly0kS2WBEJYFflEUuQ9Cq4NAvc97FZ5COK0GsJNOFnYhOl36aMpC0O21dVNXU +jXuUe9TEloWW0AZnk9p9EceBls/JgU35W2poByEBaWan+BBR45LxZIxowMWg6MT HMB00KuJDtt0zCUo/Aj/L/eDIivmJ9JMWKL8V4nhvkn7mEZIHxK4KYSnF5sGH9C1 VlI4SmBDjn+6wk4sdjKnfvafjdogQOr0lJwMWZ3ZK2hfLHmQx67mN+js5je7uflz YGCkr+qcjRzCmYTRCjwUdh8oqufulHX81Jpp0TiJ0YTENkdMPAweyaShfY3YSGGP NS4v3CapCmurFK6K9FeXbumHvNZPHYXlmdfPB5qJEWbKSRs5uisHVvjfKIDwnl+B aHfnX4O8I08MEMbn8AqSPufBC0cI8U0xt5epaCh9Ob990xTi3FYfyZM1ohKzu6sn ADVjzXkLC/1QLqlydjunCmgug086FCd6eQvW6MCgtSBlwv2NNG4= =PTAV -----END PGP SIGNATURE-----

