5
CVSSv2

CVE-2015-0971

Published: 14/05/2015 Updated: 15/05/2015
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The DER parser in Suricata prior to 2.0.8 allows remote malicious users to cause a denial of service (crash) via vectors related to SSL/TLS certificates.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

openinfosecfoundation suricata

Vendor Advisories

Kostya Kortchinsky of the Google Security Team discovered a flaw in the DER parser used to decode SSL/TLS certificates in suricata A remote attacker can take advantage of this flaw to cause suricata to crash For the stable distribution (jessie), this problem has been fixed in version 207-2+deb8u1 For the unstable distribution (sid), this probl ...