Re: Is Snort affected ? (CVE-2019-1696, CVE-2019-1704)

Snort User via Snort-devel <[email protected]> Tue, 21 May 2019 11:30:14 -0400
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <CAJ57869vbZTjZXr5Q+A761pQdG6ahirpmB3OEAt6Akp6HyxZ+Q@mail.gmail.com>
Will the blog detail on the scenario that causes the issue and the risk etc?


Thanks


On Tue, May 21, 2019 at 10:06 AM Joel Esler (jesler) <[email protected]>
wrote:

> I have verified that these vulnerabilities were corrected with 2.9.13.0.
> We recommend *all users* not using 2.9.13.0 to upgrade to 2.9.13.0 as
> soon as you can.
>
>
>
> We’ll put out a blog post soon.
>
>
>
> --
>
> Joel Esler
>
> Manager, Communities Division
>
> Cisco Talos Intelligence Group
>
> http://www.talosintelligence.com
>
>
>
> *From: *Snort-devel <[email protected]> on behalf of
> "Joel Esler (jesler) via Snort-devel" <[email protected]>
> *Reply-To: *"Joel Esler (jesler)" <[email protected]>
> *Date: *Monday, May 20, 2019 at 5:18 PM
> *To: *Snort User <[email protected]>, snort-devel <
> [email protected]>
> *Subject: *Re: [Snort-devel] Is Snort affected ? (CVE-2019-1696,
> CVE-2019-1704)
>
>
>
> Thanks,
>
>
>
> I am in touch with the product team now to clarify and if action is
> needed, to take action.
>
>
>
> --
>
> Joel Esler
>
> Manager, Communities Division
>
> Cisco Talos Intelligence Group
>
> http://www.talosintelligence.com
>
>
>
> *From: *Snort-devel <[email protected]> on behalf of
> Snort User via Snort-devel <[email protected]>
> *Reply-To: *Snort User <[email protected]>
> *Date: *Monday, May 20, 2019 at 10:40 AM
> *To: *snort-devel <[email protected]>
> *Subject: *[Snort-devel] Is Snort affected ? (CVE-2019-1696,
> CVE-2019-1704)
>
>
>
> Hi
>
>
>
>
> https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-frpwr-smb-snort
>
>
>
> In the above report, I saw -
>
>
>
> "These vulnerabilities may also affect the open-source Snort project. For
> more information, see the Snort website <https://www.snort.org/>."
>
> However, I did not see any information on the website (or I missed it)
>
>
>
> I could not find any relevant info in the ChangeLog of the most recent
> release.
>
>
>
> Can anyone provide any details or info on this?
>
>
>
> - Is Snort affected? How?
>
> - Which versions? Is a patch available? etc
>

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!