Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38xc-j7pw-37v9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow.

An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow.

EPSS

Процентиль: 66%
0.00518
Низкий

Дефекты

CWE-191

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow.

CVSS3: 9.8
nvd
больше 6 лет назад

An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow.

CVSS3: 9.8
debian
больше 6 лет назад

An issue was discovered in Suricata 4.1.x before 4.1.4. If the input o ...

EPSS

Процентиль: 66%
0.00518
Низкий

Дефекты

CWE-191