VDB

CVE-2019-10052

CVE-2019-10052 PUBLISHED

An issue was discovered in Suricata 4.1.3. If the network packet does not have the right length, the parser tries to access a part of a DHCP packet. At this point, the Rust environment runs into a panic in parse_clientid_option in the dhcp/parser.rs file.

EPSS 0.60% · 69.8th percentile

Risk Scores

EPSS Score
0.60%
69.8th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsuricata2.0.8-1build1, 2.0.9-1, 2.0.10-2
Ubuntu:18.04:LTSsuricata0, 3.2-2ubuntu3

Timeline

  • Aug 28, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›