Candidate: CVE-2019-10055 PublicDate: 2019-08-28 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10055 https://redmine.openinfosecfoundation.org/issues/2949 https://suricata-ids.org/2019/04/30/suricata-4-1-4-released/ Description: An issue was discovered in Suricata 4.1.3. The function ftp_pasv_response lacks a check for the length of part1 and part2, leading to a crash within the ftp/mod.rs file. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_suricata: upstream_suricata: needs-triage precise/esm_suricata: DNE trusty_suricata: ignored (out of standard support) trusty/esm_suricata: DNE xenial_suricata: ignored (end of standard support, was needs-triage) bionic_suricata: needs-triage disco_suricata: ignored (reached end-of-life) eoan_suricata: ignored (reached end-of-life) focal_suricata: DNE groovy_suricata: DNE hirsute_suricata: DNE impish_suricata: DNE jammy_suricata: not-affected (1:4.1.4-1) devel_suricata: not-affected (1:4.1.4-1)