First published: Tue Sep 24 2019(Updated: )
An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble in defrag.c tries to access a memory region that is not allocated, because of a lack of header_len checking.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
suricata-ids Suricata | =4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16410 is a vulnerability discovered in Suricata 4.1.4 that allows an attacker to access a memory region that is not allocated.
CVE-2019-16410 has a severity rating of 9.1 (critical).
Suricata 4.1.4 is affected by CVE-2019-16410.
Update Suricata to version 4.1.5 or later to fix CVE-2019-16410.
More information about CVE-2019-16410 can be found on the official Suricata website and the Code Intelligence website.