CVE-2014-6603Suricata vulnerability

CWE-3997 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 35.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 7
Latest updateMay 14

Description

The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debianoisf/suricata< 2.0.4-1+3

🔴Vulnerability Details

3
GHSA
GHSA-9x5x-99rm-rq9h: The SSHParseBanner function in SSH parser (app-layer-ssh2022-05-14
CVEList
CVE-2014-6603: The SSHParseBanner function in SSH parser (app-layer-ssh2014-10-07
OSV
CVE-2014-6603: The SSHParseBanner function in SSH parser (app-layer-ssh2014-10-07

📋Vendor Advisories

1
Debian
CVE-2014-6603: suricata - The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2...2014

💬Community

2
Bugzilla
CVE-2014-6603 suricata: out-of-bounds access in SSH parser2014-09-24
Bugzilla
CVE-2014-6603 suricata: out-of-bounds access in SSH parser [fedora-all]2014-09-24
CVE-2014-6603 — Suricata vulnerability | cvebase