CVE-2019-10055: Integer Overflow
Published Aug 28, 2019
·Updated
An issue was discovered in Suricata 4.1.3. The function ftppasvresponse lacks a check for the length of part1 and part2, leading to a crash within the ftp/mod.rs file.
Affected Software
1 affected component
Suricata-ids Suricata=4.1.4
Event History
Aug 28, 2019
CVE Published
via MITRE·08:13 PM
Data Sourced
via MITRE·08:13 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-10055.
2
What is the severity of CVE-2019-10055?
The severity of CVE-2019-10055 is high (7.5).
3
What is the affected software?
The affected software is Suricata version 4.1.4.
4
How can I fix CVE-2019-10055?
To fix CVE-2019-10055, update Suricata to version 4.1.4 or later.
5
Are there any additional references about this vulnerability?
Yes, you can find additional information about CVE-2019-10055 at the following references: [link1](https://redmine.openinfosecfoundation.org/issues/2949), [link2](https://suricata-ids.org/2019/04/30/suricata-4-1-4-released/).