Bug 1778736 (CVE-2019-15699) - CVE-2019-15699 suricata: the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated
Summary: CVE-2019-15699 suricata: the parser function TLSDecodeHSHelloExtensions tries...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: CVE-2019-15699
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2019-12-02 12:09 UTC by Marian Rehak
Modified: 2020-04-28 12:46 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-03-31 13:37:24 UTC
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2019-12-02 12:09:22 UTC
An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated, because the expected length of HSHelloExtensions does not match the real length of the HSHelloExtensions part of the packet.

Upstream Fix:

https://suricata-ids.org/2019/09/24/suricata-4-1-5-released/

Comment 1 Steve Grubb 2019-12-02 13:39:16 UTC
Why do we keep opening bug reports for things that are fixed? This is fixed on all supported branches and may be closed.

Comment 2 Marian Rehak 2019-12-02 13:56:14 UTC
To have this reported in our system. There's a point however. This can be closed, since components were marked notaffected from the start. Closed -> notabug.


Note You need to log in before you can comment on or make changes to this bug.