Bug 277880 - security/suricata: update to 7.0.4
Summary: security/suricata: update to 7.0.4
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Many People
Assignee: Fernando Apesteguía
URL: https://suricata.io/2024/03/19/surica...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-03-22 07:53 UTC by Franco Fichtner
Modified: 2024-03-29 17:53 UTC (History)
2 users (show)

See Also:


Attachments
update (857 bytes, patch)
2024-03-22 07:53 UTC, Franco Fichtner
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Franco Fichtner 2024-03-22 07:53:05 UTC
Created attachment 249394 [details]
update

Hi,

Suricata team put out a stable update this week.


Cheers,
Franco
Comment 1 Fernando Apesteguía freebsd_committer freebsd_triage 2024-03-26 19:21:16 UTC
This one fixes two CVEs

CVE IDs Addressed

Suricata:

    CVE-2024-28870 – HIGH

Suricata security advisories: Security Advisories · OISF/suricata · GitHub

LibHTP:

    CVE-2024-28871 – HIGH

LibHTP security advisories: Security Advisories · OISF/libhtp · GitHub
Comment 2 Fernando Apesteguía freebsd_committer freebsd_triage 2024-03-29 17:53:12 UTC
Committed,

Thanks!
Comment 3 commit-hook freebsd_committer freebsd_triage 2024-03-29 17:53:37 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=1b0ccb9849fa269e7a530760d1f43c8df2983c4c

commit 1b0ccb9849fa269e7a530760d1f43c8df2983c4c
Author:     Franco Fichtner <franco@opnsense.org>
AuthorDate: 2024-03-26 19:20:08 +0000
Commit:     Fernando Apesteguía <fernape@FreeBSD.org>
CommitDate: 2024-03-29 17:52:28 +0000

    security/suricata: update to 7.0.4

    ChangeLog: https://suricata.io/2024/03/19/suricata-7-0-4-and-6-0-17-released/

    CVEs have been RESERVED but no details have been provided yet.

    PR:             277880
    Reported by:    franco@opnsense.org
    Security:       CVE-2024-28870 CVE-2024-28871

 security/suricata/Makefile | 3 +--
 security/suricata/distinfo | 6 +++---
 2 files changed, 4 insertions(+), 5 deletions(-)