Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-8954

Опубликовано: 20 мар. 2017
Источник: debian

Описание

The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
suricatafixed2.0.6-1package
suricatano-dsawheezypackage
suricatano-dsasqueezepackage

Примечания

  • https://redmine.openinfosecfoundation.org/issues/1364

  • https://github.com/OISF/suricata/commit/17dfd59bc31a21e103e2f1216443cd1418398aa9

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.

CVSS3: 9.8
nvd
почти 9 лет назад

The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.

CVSS3: 9.8
github
больше 3 лет назад

The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.