{"id":"CVE-2019-15699","details":"An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the parser function TLSDecodeHSHelloExtensions tries to access a memory region that is not allocated, because the expected length of HSHelloExtensions does not match the real length of the HSHelloExtensions part of the packet.","modified":"2026-07-08T16:07:54.170474Z","published":"2019-09-24T20:15:11.810Z","references":[{"type":"ADVISORY","url":"https://lists.openinfosecfoundation.org/pipermail/oisf-announce/"},{"type":"ADVISORY","url":"https://suricata-ids.org/2019/09/24/suricata-4-1-5-released/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/oisf/suricata","events":[{"introduced":"14c2b6e445b3e8b5f802c4538397c12bfd3f831d"},{"last_affected":"14c2b6e445b3e8b5f802c4538397c12bfd3f831d"}],"database_specific":{"cpe":"cpe:2.3:a:suricata-ids:suricata:4.1.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.1.4"},{"last_affected":"4.1.4"}],"source":"CPE_STRING"}}],"versions":["4.1.4","suricata-4.1.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15699.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}