CVE-2014-6603
EPSS 0.47%
描述
The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.
如何修補 CVE-2014-6603
要修補 CVE-2014-6603,請將受影響套件升級到下列已修補版本。
- Debian/suricata—升級至 2.0.4-1 或更新版本
CVE-2014-6603 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.0.4-1