CVE-2015-8954: Critical severity suricata vulnerability
Published Feb 9, 2015
·Updated
The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.
Affected Software
1 affected component
Openinfosecfoundation Suricata<=2.0.5
Event History
Feb 9, 2015
Data Sourced
08:33 AM
SeverityAffected Software
Mar 20, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8954?
CVE-2015-8954 is considered a medium severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2015-8954?
To fix CVE-2015-8954, upgrade Suricata to version 2.0.6 or later.
3
What can attackers do by exploiting CVE-2015-8954?
By exploiting CVE-2015-8954, attackers can bypass the intrusion-prevention functionality of Suricata through crafted HTTP requests.
4
Which versions of Suricata are affected by CVE-2015-8954?
Suricata versions prior to 2.0.6, particularly up to version 2.0.5, are affected by CVE-2015-8954.
5
Does CVE-2015-8954 affect all Suricata installations?
CVE-2015-8954 specifically affects installations of Suricata before version 2.0.6.