CVE Vulnerabilities

CVE-2018-6794

Protection Mechanism Failure

Published: Feb 07, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow and sends data before the 3-way handshake is complete, then the data sent by the malicious server will be accepted by web clients such as a web browser or Linux CLI utilities, but ignored by Suricata IDS signatures. This mostly affects IDS signatures for the HTTP protocol and TCP stream content; signatures for TCP packets will inspect such network traffic as usual.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

NameVendorStart VersionEnd Version
SuricataSuricata-ids*4.0.4 (excluding)
SuricataUbuntuartful*
SuricataUbuntubionic*
SuricataUbuntucosmic*
SuricataUbuntudisco*
SuricataUbuntueoan*
SuricataUbuntuesm-apps/bionic*
SuricataUbuntuesm-apps/xenial*
SuricataUbuntutrusty*
SuricataUbuntuupstream*
SuricataUbuntuxenial*

References