Description
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-commmon.c has an integer overflow during a length check.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-2318 | Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-commmon.c has an integer overflow during a length check. |
References
History
Tue, 22 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oisf
Oisf suricata |
|
| CPEs | cpe:2.3:a:oisf:suricata:4.0.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Suricata-ids
Suricata-ids suricata |
Oisf
Oisf suricata |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T07:32:01.718Z
Reserved: 2018-04-20T00:00:00.000Z
Link: CVE-2018-10244
No data.
Status : Modified
Published: 2019-04-04T16:29:00.273
Modified: 2024-11-21T03:41:05.947
Link: CVE-2018-10244
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD