In Suricata before 6.0.13 (when there is an adversary who...
High severity
Unreviewed
Published
Jun 19, 2023
to the GitHub Advisory Database
•
Updated Nov 3, 2025
Description
Published by the National Vulnerability Database
Jun 19, 2023
Published to the GitHub Advisory Database
Jun 19, 2023
Last updated
Nov 3, 2025
In Suricata before 6.0.13 (when there is an adversary who controls an external source of rules), a dataset filename, that comes from a rule, may trigger absolute or relative directory traversal, and lead to write access to a local filesystem. This is addressed in 6.0.13 by requiring allow-absolute-filenames and allow-write (in the datasets rules configuration section) if an installation requires traversal/writing in this situation.
References