CVE-2019-10054: Integer Underflow
Published Aug 28, 2019
·Updated
An issue was discovered in Suricata 4.1.3. The function processreplyrecordv3 lacks a check for the length of reply.data. It causes an invalid memory access and the program crashes within the nfs/nfs3.rs file.
Affected Software
1 affected component
Suricata-ids Suricata=4.1.3
Event History
Aug 28, 2019
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-10054.
2
What is the affected version of Suricata?
The affected version of Suricata is 4.1.3.
3
What is the severity level of CVE-2019-10054?
The severity level of CVE-2019-10054 is high with a CVSS score of 7.5.
4
What is the CWE ID associated with this vulnerability?
The CWE ID associated with this vulnerability is CWE-191 and CWE-20.
5
How can I fix CVE-2019-10054 in Suricata?
To fix CVE-2019-10054 in Suricata, update to a version that includes the fix, such as Suricata 4.1.4 or later.