Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10242

Опубликовано: 04 апр. 2019
Источник: debian

Описание

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
suricatafixed1:4.0.5-1package
suricatano-dsastretchpackage

Примечания

  • https://redmine.openinfosecfoundation.org/issues/2544

  • https://redmine.openinfosecfoundation.org/issues/2542

  • https://github.com/OISF/suricata/commit/9ba89a31efc89ec5cb72326dbcb9166b098f3ea0

  • https://suricata-ids.org/2018/07/18/suricata-4-0-5-available/

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.

CVSS3: 7.5
nvd
почти 7 лет назад

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.

CVSS3: 7.5
github
больше 3 лет назад

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.