CVE-2019-16410: Critical severity suricata vulnerability
Published Sep 24, 2019
·Updated
An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble in defrag.c tries to access a memory region that is not allocated, because of a lack of headerlen checking.
Affected Software
1 affected component
Suricata-ids Suricata=4.1.4
Event History
Sep 24, 2019
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16410?
CVE-2019-16410 is a vulnerability discovered in Suricata 4.1.4 that allows an attacker to access a memory region that is not allocated.
2
How severe is CVE-2019-16410?
CVE-2019-16410 has a severity rating of 9.1 (critical).
3
What software is affected by CVE-2019-16410?
Suricata 4.1.4 is affected by CVE-2019-16410.
4
How can I fix CVE-2019-16410?
Update Suricata to version 4.1.5 or later to fix CVE-2019-16410.
5
Where can I find more information about CVE-2019-16410?
More information about CVE-2019-16410 can be found on the official Suricata website and the Code Intelligence website.