USN-8766-1: Suricata-Update vulnerability
Ubuntu patches Suricata-Update path validation flaw allowing arbitrary file writes outside the rules directory from malicious rule archives.
Ubuntu security notice USN-8766-1 fixes a Suricata-Update vulnerability discovered by Guillem Lefait. The tool did not properly validate destination paths when extracting files referenced by downloaded rule archives, allowing an attacker to write arbitrary files outside the configured rules directory. Users are advised to update the suricata-update package.
- Unvalidated extraction paths allow arbitrary file writes outside rules directory
- Attack vector requires malicious rule archive referenced during update
Guillem Lefait discovered that Suricata-Update did not properly validate destination paths when extracting files referenced by downloaded rule archives. An attacker could possibly use this issue to write arbitrary files outside the configured rules directory.
This source does not provide full text. Read it at ubuntu.com.