CVE-2019-10053Out-of-bounds Read in Suricata

Severity
9.8CRITICALNVD
EPSS
0.5%
top 33.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13
Latest updateMay 24

Description

An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDsuricata-ids/suricata4.1.04.1.4
Debianoisf/suricata< 1:4.1.4-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-38xc-j7pw-37v9: An issue was discovered in Suricata 42022-05-24
OSV
CVE-2019-10053: An issue was discovered in Suricata 42019-05-13
CVEList
CVE-2019-10053: An issue was discovered in Suricata 42019-05-13

📋Vendor Advisories

1
Debian
CVE-2019-10053: suricata - An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the func...2019

💬Community

3
Bugzilla
CVE-2019-10053 suricata: heap-based buffer over-read in function SSHParseBanner [fedora-all]2019-05-14
Bugzilla
CVE-2019-10053 suricata: heap-based buffer over-read in function SSHParseBanner [epel-7]2019-05-14
Bugzilla
CVE-2019-10053 suricata: heap-based buffer over-read in function SSHParseBanner2019-05-14
CVE-2019-10053 — Out-of-bounds Read in Suricata | cvebase