PT-2017-3436 · Open Information Security Foundation · Suricata
Ajaxtpm
+1
·
Published
2017-10-13
·
Updated
2020-10-27
·
CVE-2017-15377
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Suricata versions prior to 4.x
Description
The issue is related to the DetectEngineContentInspection component in Suricata, which can be triggered by crafted network traffic with a certain signature. This causes the search engine to perform redundant checks on the content, leading to potential denial of service. The search engine fails to stop when it should after no match is found, instead stopping only upon reaching the inspection-recursion-limit, which is 3000 by default. An attacker could exploit this to cause a denial of service using specially crafted network traffic, resulting in excessive checks.
Recommendations
For Suricata versions prior to 4.x, consider updating to version 4.x or later to resolve the issue. As a temporary workaround, consider adjusting the inspection-recursion-limit to a lower value to minimize the risk of exploitation. Restrict access to the DetectEngineContentInspection component to minimize the risk of denial of service attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Suricata