CVE-2017-15377 -- suricataID: oval:org.secpod.oval:def:2001221 | Date: (C)2019-06-03 (M)2023-12-20 |
Class: VULNERABILITY | Family: unix |
In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspection in detect-engine-content-inspection.c. The search engine doesn"t stop when it should after no match is found; instead, it stops only upon reaching inspection-recursion-limit .
Platform: |
Debian 8.x |
Debian 9.x |