CVE-2019-10053: Suricata-Ids Suricata
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the program runs into a heap-based buffer over-read. This occurs because the erroneous search for \r results in an integer underflow.
Affected products
- Suricata-Ids Suricata: from 4.1.0, before 4.1.4 (fixed in 4.1.4)
Published 2019-05-13. Last modified 2026-06-17.