An issue exists in Suricata 4.1.x prior to 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
suricata-ids suricata |