Re: Is Snort affected ? (CVE-2019-1696, CVE-2019-1704)

"Joel Esler \(jesler\) via Snort-devel" <[email protected]> Tue, 21 May 2019 14:06:42 +0000
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <[email protected]>
I have verified that these vulnerabilities were corrected with 2.9.13.0.  We recommend all users not using 2.9.13.0 to upgrade to 2.9.13.0 as soon as you can.

We’ll put out a blog post soon.

--
Joel Esler
Manager, Communities Division
Cisco Talos Intelligence Group
http://www.talosintelligence.com

From: Snort-devel <[email protected]> on behalf of "Joel Esler (jesler) via Snort-devel" <[email protected]>
Reply-To: "Joel Esler (jesler)" <[email protected]>
Date: Monday, May 20, 2019 at 5:18 PM
To: Snort User <[email protected]>, snort-devel <[email protected]>
Subject: Re: [Snort-devel] Is Snort affected ? (CVE-2019-1696, CVE-2019-1704)

Thanks,

I am in touch with the product team now to clarify and if action is needed, to take action.

--
Joel Esler
Manager, Communities Division
Cisco Talos Intelligence Group
http://www.talosintelligence.com

From: Snort-devel <[email protected]> on behalf of Snort User via Snort-devel <[email protected]>
Reply-To: Snort User <[email protected]>
Date: Monday, May 20, 2019 at 10:40 AM
To: snort-devel <[email protected]>
Subject: [Snort-devel] Is Snort affected ? (CVE-2019-1696, CVE-2019-1704)

Hi

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-frpwr-smb-snort

In the above report, I saw -

"These vulnerabilities may also affect the open-source Snort project. For more information, see the Snort website<https://www.snort.org/>."
However, I did not see any information on the website (or I missed it)

I could not find any relevant info in the ChangeLog of the most recent release.

Can anyone provide any details or info on this?

- Is Snort affected? How?
- Which versions? Is a patch available? etc

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!