Project

General

Profile

Actions

Security #8683

closed
OT PA

ftp: RETR without PORT/PASV triggers permanent app-layer detection bypass (7.0.x backport)

Security #8683: ftp: RETR without PORT/PASV triggers permanent app-layer detection bypass (7.0.x backport)

Added by OISF Ticketbot about 2 months ago. Updated 28 days ago.

Status:
Rejected
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:
Severity:
LOW
Disclosure Date:

JI Updated by Jason Ish about 2 months ago Actions #1

  • GHSA set to GHSA-56wx-7hqh-wfgr

PA Updated by Philippe Antoine about 2 months ago Actions #2

  • Target version changed from 7.0.18 to 7.0.17

JI Updated by Jason Ish about 2 months ago Actions #3

  • Severity set to LOW

PA Updated by Philippe Antoine about 2 months ago Actions #4

  • Status changed from Assigned to In Review

PA Updated by Philippe Antoine about 1 month ago Actions #5

  • Status changed from In Review to Rejected

As discussed with Victor, this fix is too intrusive for QA for a low severity security issue and 7 getting eol

See https://github.com/OISF/suricata/pull/15753#issuecomment-4848274559

JI Updated by Jason Ish about 1 month ago Actions #6

GHSA updated to remove upgrading to 7.0.17 as a fix.

JI Updated by Jason Ish about 1 month ago Actions #7

  • CVE set to 2026-63450

JI Updated by Jason Ish 28 days ago Actions #8

  • Private changed from Yes to No
Actions

Also available in: PDF Atom