CVE-2018-10242: High severity suricata vulnerability
Published Apr 4, 2019
·Updated
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.
Affected Software
3 affected components
OISF Suricata=4.0.4
Debian Debian Linux=8.0
Suricata-ids Suricata=4.0.4
Event History
Apr 4, 2019
CVE Published
via MITRE·02:59 PM
Data Sourced
via MITRE·02:59 PM
Description
Frequently Asked Questions
1
What is CVE-2018-10242?
CVE-2018-10242 is a vulnerability in Suricata version 4.0.4 that incorrectly handles the parsing of the SSH banner.
2
What is the severity of CVE-2018-10242?
The severity of CVE-2018-10242 is high with a CVSS score of 7.5.
3
How does CVE-2018-10242 affect Suricata?
CVE-2018-10242 affects Suricata version 4.0.4.
4
How does CVE-2018-10242 affect Debian Linux?
CVE-2018-10242 affects Debian Linux version 8.0.
5
How can I fix CVE-2018-10242?
To fix CVE-2018-10242, update Suricata to version 4.0.5 or later.