Candidate: CVE-2015-0971 PublicDate: 2015-05-14 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0971 http://suricata-ids.org/2015/05/06/suricata-2-0-8-available/ Description: The DER parser in Suricata before 2.0.8 allows remote attackers to cause a denial of service (crash) via vectors related to SSL/TLS certificates. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Kostya Kortchinsky Assigned-to: CVSS: Patches_suricata: upstream: https://github.com/inliniac/suricata/commit/fa73a0bb8f312fd0a95cc70f6b3ee4e4997bdba7 upstream_suricata: released (2.0.8) precise_suricata: ignored (reached end-of-life) precise/esm_suricata: DNE (precise was needed) trusty_suricata: released (1.4.7-1ubuntu1.1) trusty/esm_suricata: DNE (trusty was released [1.4.7-1ubuntu1.1]) utopic_suricata: ignored (reached end-of-life) vivid_suricata: ignored (reached end-of-life) vivid/stable-phone-overlay_suricata: DNE vivid/ubuntu-core_suricata: DNE wily_suricata: not-affected (2.0.8-1) xenial_suricata: not-affected (2.0.8-1) yakkety_suricata: not-affected (2.0.8-1) zesty_suricata: not-affected (2.0.8-1) devel_suricata: not-affected (2.0.8-1)