Skip to main content

Kaspersky identifies seven vulnerabilities in open-source projects Suricata and FreeRDP

August 22, 2024

Kaspersky has uncovered seven vulnerabilities, two of which could allow arbitrary code execution, in the widely used open-source projects Suricata and FreeRDP during pre-release penetration testing of company's products.

Kaspersky's security experts have found seven vulnerabilities in the widely used open-source projects Suricata and FreeRDP. Two of these vulnerabilities, CVE-2024-32664 and CVE-2024-32039, could potentially allow attackers to execute arbitrary code on a vulnerable system, while others could enable unauthorized memory access.

These vulnerabilities were discovered during pre-release penetration testing as part of the security assessment of KasperskyOS-based products, including Kaspersky Thin Client (KTC) and Kaspersky IoT Secure Gateway (KISG), which integrate the open-source components Suricata and FreeRDP. Our team promptly reported these vulnerabilities to the respective library developers.

The open-source community validated the findings and assigned seven CVEs:

  • FreeRDP:
    • CVE-2024-32041
    • CVE-2024-32039
    • CVE-2024-32040
    • CVE-2024-32458
    • CVE-2024-32459
    • CVE-2024-32460
  • Suricata:
    • CVE-2024-32664

Along with the reports, Kaspersky provided fuzzing tests instrumental in identifying issues in FreeRDP. The open-source community used these tests to uncover an additional about 10 vulnerabilities. All vulnerabilities were patched in both the open-source projects and Kaspersky’s products before the public release of new versions.

"The principle of 'secure by design' extends beyond system architecture to encompass the entire development process," said Denis Skvortsov, lead application security specialist at Kaspersky. "By rigorously testing all system components before release, we contributed to resolving severe issues in two widely-used open-source projects. We are grateful to the Suricata and FreeRDP maintainers for their swift response to our findings and the rapid deployment of patches."

Kaspersky strongly encourages users to update to the latest versions of Suricata and FreeRDP to ensure their systems are protected. The most up-to-date versions at the time of this release are:

  • Suricata: 6.0.19 and 7.0.5
  • FreeRDP: 2.11.7 and 3.5.1

For further details on the discovered vulnerabilities, please visit Securelist.com.

Kaspersky identifies seven vulnerabilities in open-source projects Suricata and FreeRDP

Kaspersky has uncovered seven vulnerabilities, two of which could allow arbitrary code execution, in the widely used open-source projects Suricata and FreeRDP during pre-release penetration testing of company's products.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases