Description
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1751-1 | suricata security update |
EUVD |
EUVD-2018-2316 | Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check. |
References
History
Tue, 22 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oisf
Oisf suricata |
|
| CPEs | cpe:2.3:a:oisf:suricata:4.0.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Suricata-ids
Suricata-ids suricata |
Oisf
Oisf suricata |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T07:32:01.759Z
Reserved: 2018-04-20T00:00:00.000Z
Link: CVE-2018-10242
No data.
Status : Modified
Published: 2019-04-04T15:29:00.377
Modified: 2024-11-21T03:41:05.650
Link: CVE-2018-10242
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD