Candidate: CVE-2018-10244 PublicDate: 2019-04-04 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10244 https://suricata-ids.org/2018/07/18/suricata-4-0-5-available/ Description: Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-commmon.c has an integer overflow during a length check. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_suricata: upstream_suricata: needs-triage precise/esm_suricata: DNE trusty_suricata: ignored (reached end-of-life) trusty/esm_suricata: DNE (trusty was needs-triage) xenial_suricata: ignored (end of standard support, was needs-triage) bionic_suricata: needs-triage cosmic_suricata: ignored (reached end-of-life) disco_suricata: ignored (reached end-of-life) eoan_suricata: ignored (reached end-of-life) focal_suricata: DNE groovy_suricata: DNE hirsute_suricata: DNE impish_suricata: DNE jammy_suricata: not-affected (1:4.0.5-1) devel_suricata: not-affected (1:4.0.5-1)