Re: Is Snort affected ? (CVE-2019-1696, CVE-2019-1704)
Snort User via Snort-devel <[email protected]> Tue, 21 May 2019 11:30:14 -0400
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <CAJ57869vbZTjZXr5Q+A761pQdG6ahirpmB3OEAt6Akp6HyxZ+Q@mail.gmail.com> |
Will the blog detail on the scenario that causes the issue and the risk etc? Thanks On Tue, May 21, 2019 at 10:06 AM Joel Esler (jesler) <[email protected]> wrote: > I have verified that these vulnerabilities were corrected with 2.9.13.0. > We recommend *all users* not using 2.9.13.0 to upgrade to 2.9.13.0 as > soon as you can. > > > > We’ll put out a blog post soon. > > > > -- > > Joel Esler > > Manager, Communities Division > > Cisco Talos Intelligence Group > > http://www.talosintelligence.com > > > > *From: *Snort-devel <[email protected]> on behalf of > "Joel Esler (jesler) via Snort-devel" <[email protected]> > *Reply-To: *"Joel Esler (jesler)" <[email protected]> > *Date: *Monday, May 20, 2019 at 5:18 PM > *To: *Snort User <[email protected]>, snort-devel < > [email protected]> > *Subject: *Re: [Snort-devel] Is Snort affected ? (CVE-2019-1696, > CVE-2019-1704) > > > > Thanks, > > > > I am in touch with the product team now to clarify and if action is > needed, to take action. > > > > -- > > Joel Esler > > Manager, Communities Division > > Cisco Talos Intelligence Group > > http://www.talosintelligence.com > > > > *From: *Snort-devel <[email protected]> on behalf of > Snort User via Snort-devel <[email protected]> > *Reply-To: *Snort User <[email protected]> > *Date: *Monday, May 20, 2019 at 10:40 AM > *To: *snort-devel <[email protected]> > *Subject: *[Snort-devel] Is Snort affected ? (CVE-2019-1696, > CVE-2019-1704) > > > > Hi > > > > > https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-frpwr-smb-snort > > > > In the above report, I saw - > > > > "These vulnerabilities may also affect the open-source Snort project. For > more information, see the Snort website <https://www.snort.org/>." > > However, I did not see any information on the website (or I missed it) > > > > I could not find any relevant info in the ChangeLog of the most recent > release. > > > > Can anyone provide any details or info on this? > > > > - Is Snort affected? How? > > - Which versions? Is a patch available? etc > _______________________________________________ Snort-devel mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-devel Please visit http://blog.snort.org for the latest news about Snort!