CVE-2016-10728Improper Input Validation in Suricata

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 39.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 14

Description

An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

Debianoisf/suricata< 3.1.2-1+3

🔴Vulnerability Details

3
GHSA
GHSA-hg98-gwg7-w72p: An issue was discovered in Suricata before 32022-05-14
CVEList
CVE-2016-10728: An issue was discovered in Suricata before 32018-07-23
OSV
CVE-2016-10728: An issue was discovered in Suricata before 32018-07-23

📋Vendor Advisories

1
Debian
CVE-2016-10728: suricata - An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is r...2016
CVE-2016-10728 — Improper Input Validation in Suricata | cvebase