In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Suricata | Oisf | * | 6.0.13 (excluding) |
Suricata | Ubuntu | bionic | * |
Suricata | Ubuntu | kinetic | * |
Suricata | Ubuntu | lunar | * |
Suricata | Ubuntu | mantic | * |
Suricata | Ubuntu | trusty | * |
Suricata | Ubuntu | xenial | * |