Input validation error in Suricata - CVE-2016-10728

 

Input validation error in Suricata - CVE-2016-10728

Published: July 23, 2018 / Updated: July 17, 2020


Vulnerability identifier: #VU31264
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10728
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection.


Affected software

Suricata

How to mitigate CVE-2016-10728

Install update from vendor's website.

Suricata - update to 3.1.2

External References

Related Security Bulletins