OSV 1.4.0 · unreviewed · 修改于 2025-11-04 05:30
发布时间
2021-12-17 08:00
GitHub 审查时间
—
NVD 发布时间
2021-12-16 13:15
源文件
advisories/unreviewed/2021/12/GHSA-cfcf-x7x2-gpf8/GHSA-cfcf-x7x2-gpf8.json
An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to inject an RST ACK with a random TCP md5header option. Then, the client can send an HTTP GET request with a forbidden URL. The server will ignore the RST ACK and send the response HTTP packet for the client's request. These packets will not trigger a Suricata reject action.
该公告没有提供结构化的受影响软件包信息。