CVE-2019-10053: Integer Underflow
An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-10053?
CVE-2019-10053 is a vulnerability discovered in Suricata 4.1.x before 4.1.4 that can lead to a heap-based buffer over-read due to an integer underflow.
How severe is CVE-2019-10053?
CVE-2019-10053 has a severity rating of 9.8, which is classified as critical.
What software versions are affected by CVE-2019-10053?
Suricata versions between 4.1.0 and 4.1.4 are affected by CVE-2019-10053.
How can CVE-2019-10053 be fixed?
To fix CVE-2019-10053, update Suricata to version 4.1.4 or later.
Where can I find more information about CVE-2019-10053?
More information about CVE-2019-10053 can be found in the reference links provided: [link1](https://lists.openinfosecfoundation.org/pipermail/oisf-announce/) and [link2](https://suricata-ids.org/2019/04/30/suricata-4-1-4-released/).