An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble in defrag.c tries to access a memory region that is not allocated, because of a lack of header_len checking.
{
"binaries": [
{
"binary_version": "3.2-2ubuntu3",
"binary_name": "libhtp-0.5.23-1"
},
{
"binary_version": "3.2-2ubuntu3",
"binary_name": "suricata"
},
{
"binary_version": "3.2-2ubuntu3",
"binary_name": "suricata-hyperscan"
},
{
"binary_version": "3.2-2ubuntu3",
"binary_name": "suricata-oinkmaster"
}
]
}