CVE-2018-18956

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
05/11/2018
Last modified:
24/08/2020

Description

The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input to the SMTP parser, as exploited in the wild in November 2018.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:suricata-ids:suricata:*:*:*:*:*:*:*:* 4.0.0 (including) 4.0.6 (excluding)