[Git][security-tracker-team/security-tracker][master] Add new suricata issues
    Salvatore Bonaccorso (@carnil) 
    carnil at debian.org
       
    Thu Oct  2 05:06:08 BST 2025
    
    
  
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b7e84a95 by Salvatore Bonaccorso at 2025-10-02T06:05:47+02:00
Add new suricata issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -46,12 +46,30 @@ CVE-2025-59685 (Kazaar 1.25.12 allows a JWT with none in the alg field.)
 	NOT-FOR-US: Kazaar
 CVE-2025-59684 (DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.)
 	NOT-FOR-US: DigiSign DigiSigner ONE
+CVE-2025-59150
+	- suricata <not-affected> (Vulnerable code never present in a Debian released version, 8.0.x only issue)
+	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-mhv7-qfmj-m3f3
+	NOTE: https://github.com/OISF/suricata/commit/d590fdfe42e995fd558315f0c24f9a352e21479d (suricata-8.0.1)
+	NOTE: https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018
+	NOTE: https://redmine.openinfosecfoundation.org/issues/7881
 CVE-2025-59149 (Suricata is a network IDS, IPS and NSM engine developed by the OISF (O ...)
-	TODO: check
+	- suricata <not-affected> (Vulnerable code never present in a Debian released version, 8.0.x only issue)
+	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-vxcg-38x4-gj7j
+	NOTE: https://github.com/OISF/suricata/commit/38a2cba5c397002047d84645f5ab770ff88020e1 (suricata-8.0.1)
+	NOTE: https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018
+	NOTE: https://redmine.openinfosecfoundation.org/issues/7861
 CVE-2025-59148 (Suricata is a network IDS, IPS and NSM engine developed by the OISF (O ...)
-	TODO: check
+	- suricata <not-affected> (Vulnerable code never present in a Debian released version, 8.0.x only issue)
+	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-5qf6-92xg-3rr3
+	NOTE: https://github.com/OISF/suricata/commit/9f32550e18f97ea5d610dd7c36aab0ba142c096c (suricata-8.0.1)
+	NOTE: https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018
+	NOTE: https://redmine.openinfosecfoundation.org/issues/7838
 CVE-2025-59147 (Suricata is a network IDS, IPS and NSM engine developed by the OISF (O ...)
-	TODO: check
+	- suricata 1:8.0.1-1
+	NOTE: https://github.com/OISF/suricata/security/advisories/GHSA-v8hv-6v7x-4c2r
+	NOTE: https://github.com/OISF/suricata/commit/be6315dba0d9101b11d16e9dacfe2822b3792f1b (suricata-8.0.1)
+	NOTE: https://github.com/OISF/suricata/commit/e91b03c90385db15e21cf1a0e85b921bf92b039e (suricata-7.0.12)
+	NOTE: https://forum.suricata.io/t/suricata-8-0-1-and-7-0-12-released/6018
 CVE-2025-58769 (auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In v ...)
 	NOT-FOR-US: auth0-PHP
 CVE-2025-58055 (Discourse is an open-source community discussion platform. In versions ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b7e84a95ebe0fa420a9e2d850c15ed340e499942
-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b7e84a95ebe0fa420a9e2d850c15ed340e499942
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251002/f2aacb11/attachment.htm>
    
    
More information about the debian-security-tracker-commits
mailing list