Your submission was sent successfully! Close

CVE-2015-8954

Published: 20 March 2017

The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.

Priority

Medium

CVSS 3 base score: 9.8

Status

Package Release Status
suricata
Launchpad, Ubuntu, Debian
artful Not vulnerable

bionic Not vulnerable

cosmic Not vulnerable

disco Not vulnerable

precise Does not exist
(precise was needs-triage)
trusty Does not exist
(trusty was needed)
upstream
Released (2.0.6-1)
xenial Not vulnerable
(3.0-1)
yakkety Not vulnerable

zesty Not vulnerable