CVE-2016-10728: Input Validation
An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the toclient direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-10728?
CVE-2016-10728 is a vulnerability in Suricata IDS that can lead to missed detection if an ICMPv4 error packet is received as the first packet on a flow in the to_client direction.
What is the severity of CVE-2016-10728?
The severity of CVE-2016-10728 is medium, with a severity value of 5.3.
How does CVE-2016-10728 affect Suricata IDS?
CVE-2016-10728 affects Suricata IDS versions up to and including 3.1.2.
How can CVE-2016-10728 be exploited?
CVE-2016-10728 can be exploited by sending an ICMPv4 error packet as the first packet on a flow in the to_client direction, which confuses the rule grouping lookup logic in Suricata IDS.
Is there a fix for CVE-2016-10728?
Yes, upgrading to Suricata IDS version 3.1.3 or later fixes CVE-2016-10728.