CVE-2019-10053 PUBLISHED

An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow.

EPSS 0.52% · 66.6th percentile

Risk Scores

EPSS Score
0.52%
66.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsuricata0, 2.0.8-1build1, 2.0.9-1
Ubuntu:18.04:LTSsuricata0, 3.2-2ubuntu3

Timeline

References

Open in Interactive Console →