PT-2017-3436 · Open Information Security Foundation · Suricata

Ajaxtpm

+1

·

Published

2017-10-13

·

Updated

2020-10-27

·

CVE-2017-15377

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Suricata versions prior to 4.x
Description The issue is related to the DetectEngineContentInspection component in Suricata, which can be triggered by crafted network traffic with a certain signature. This causes the search engine to perform redundant checks on the content, leading to potential denial of service. The search engine fails to stop when it should after no match is found, instead stopping only upon reaching the inspection-recursion-limit, which is 3000 by default. An attacker could exploit this to cause a denial of service using specially crafted network traffic, resulting in excessive checks.
Recommendations For Suricata versions prior to 4.x, consider updating to version 4.x or later to resolve the issue. As a temporary workaround, consider adjusting the inspection-recursion-limit to a lower value to minimize the risk of exploitation. Restrict access to the DetectEngineContentInspection component to minimize the risk of denial of service attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00261
CVE-2017-15377
DLA-1603-1

Affected Products

Suricata