Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-15699

Опубликовано: 24 сент. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4
CVSS3: 9.1

Описание

An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated, because the expected length of HSHelloExtensions does not match the real length of the HSHelloExtensions part of the packet.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

1:4.1.5-1
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/jammy

not-affected

1:4.1.5-1
esm-apps/noble

not-affected

1:4.1.5-1
esm-apps/resolute

not-affected

1:4.1.5-1
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

Показывать по

EPSS

Процентиль: 75%
0.01645
Низкий

6.4 Medium

CVSS2

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
почти 7 лет назад

An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated, because the expected length of HSHelloExtensions does not match the real length of the HSHelloExtensions part of the packet.

CVSS3: 9.1
debian
почти 7 лет назад

An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon rec ...

CVSS3: 9.1
github
больше 4 лет назад

An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated, because the expected length of HSHelloExtensions does not match the real length of the HSHelloExtensions part of the packet.

EPSS

Процентиль: 75%
0.01645
Низкий

6.4 Medium

CVSS2

9.1 Critical

CVSS3