An issue was discovered in Suricata 4.1.3. The function process_reply_record_v3 lacks a check for the length of reply.data. It causes an invalid memory access and the program crashes within the nfs/nfs3.rs file.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://suricata-ids.org/2019/04/30/suricata-4-1-4-released/ | release notes vendor advisory |
https://redmine.openinfosecfoundation.org/issues/2943 | third party advisory issue tracking exploit |