The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://suricata-ids.org/2015/01/15/suricata-2-0-6-available/ | release notes vendor advisory |
https://redmine.openinfosecfoundation.org/issues/1364 | third party advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777523 | third party advisory |