Candidate: CVE-2017-7177 PublicDate: 2017-03-18 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7177 https://redmine.openinfosecfoundation.org/issues/2019 https://github.com/inliniac/suricata/commit/4a04f814b15762eb446a5ead4d69d021512df6f8 Description: Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856649 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_suricata: upstream_suricata: released (3.2.1-1) precise_suricata: ignored (reached end-of-life) precise/esm_suricata: DNE (precise was needs-triage) trusty_suricata: ignored (reached end-of-life) trusty/esm_suricata: DNE (trusty was needed) vivid/stable-phone-overlay_suricata: DNE vivid/ubuntu-core_suricata: DNE xenial_suricata: ignored (end of standard support, was needed) yakkety_suricata: ignored (reached end-of-life) zesty_suricata: ignored (reached end-of-life) artful_suricata: needed bionic_suricata: needed cosmic_suricata: ignored (reached end-of-life) disco_suricata: ignored (reached end-of-life) eoan_suricata: ignored (reached end-of-life) focal_suricata: DNE groovy_suricata: DNE hirsute_suricata: DNE impish_suricata: DNE jammy_suricata: not-affected (3.2.1-1) devel_suricata: not-affected (3.2.1-1)