CVE-2018-18956: Suricata-Ids Suricata
High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.
The ProcessMimeEntity function in util-decode-mime.c in Suricata 4.x before 4.0.6 allows remote attackers to cause a denial of service (segfault and daemon crash) via crafted input to the SMTP parser, as exploited in the wild in November 2018.
Affected products
- Suricata-Ids Suricata: from 4.0.0, before 4.0.6 (fixed in 4.0.6)
Published 2018-11-05. Last modified 2026-06-17.