An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1508-1 | suricata security update |
EUVD |
EUVD-2016-1726 | An issue was discovered in Suricata before 3.1.2. If an ICMPv4 error packet is received as the first packet on a flow in the to_client direction, it confuses the rule grouping lookup logic. The toclient inspection will then continue with the wrong rule group. This can lead to missed detection. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T03:30:20.166Z
Reserved: 2018-07-23T00:00:00.000Z
Link: CVE-2016-10728
No data.
Status : Modified
Published: 2018-07-23T20:29:00.240
Modified: 2024-11-21T02:44:36.587
Link: CVE-2016-10728
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD