CVE-2014-6603: Openinfosecfoundation Suricata

Medium severity, CVSS 5.0. EPSS: 3.2% chance of exploitation in the next 30 days.

The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.

Affected products

  • Openinfosecfoundation Suricata: up to and including 2.0.3-2; version 2.0.1-1 only; version 2.0.1-2 only; version 2.0.2-1 only; version 2.0.2-2 only; version 2.0.3-1 only

Published 2014-10-07. Last modified 2026-06-17.