CVE-2014-6603

The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openinfosecfoundation:suricata:*:*:*:*:*:*:*:*
cpe:2.3:a:openinfosecfoundation:suricata:2.0.1-1:*:*:*:*:*:*:*
cpe:2.3:a:openinfosecfoundation:suricata:2.0.1-2:*:*:*:*:*:*:*
cpe:2.3:a:openinfosecfoundation:suricata:2.0.2-1:*:*:*:*:*:*:*
cpe:2.3:a:openinfosecfoundation:suricata:2.0.2-2:*:*:*:*:*:*:*
cpe:2.3:a:openinfosecfoundation:suricata:2.0.3-1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2014-10-07 14:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-6603

Mitre link : CVE-2014-6603

CVE.ORG link : CVE-2014-6603


JSON object : View

Products Affected

openinfosecfoundation

  • suricata
CWE
CWE-399

Resource Management Errors