Out-of-bounds read in Suricata - CVE-2019-15699

 

Out-of-bounds read in Suricata - CVE-2019-15699

Published: September 24, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35478
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15699
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.

An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated, because the expected length of HSHelloExtensions does not match the real length of the HSHelloExtensions part of the packet.


Affected software

Suricata

How to mitigate CVE-2019-15699

Install update from vendor's website.


External References

Related Security Bulletins