{"id":"CVE-2019-16411","details":"An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function IPV4OptValidateTimestamp in decode-ipv4.c tries to access a memory region that is not allocated. There is a check for o-\u003elen \u003c 5 (corresponding to 2 bytes of header and 3 bytes of data). Then, \"flag = *(o-\u003edata + 3)\" places one beyond the 3 bytes, because the code should have been \"flag = *(o-\u003edata + 1)\" instead.","modified":"2026-07-08T20:29:28.072716Z","published":"2019-09-24T20:15:11.967Z","references":[{"type":"WEB","url":"https://www.code-intelligence.com/cve-2019-16411"},{"type":"ADVISORY","url":"https://lists.openinfosecfoundation.org/pipermail/oisf-announce/"},{"type":"ADVISORY","url":"https://suricata-ids.org/2019/09/24/suricata-4-1-5-released/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/oisf/suricata","events":[{"introduced":"14c2b6e445b3e8b5f802c4538397c12bfd3f831d"},{"last_affected":"14c2b6e445b3e8b5f802c4538397c12bfd3f831d"}],"database_specific":{"cpe":"cpe:2.3:a:suricata-ids:suricata:4.1.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.1.4"},{"last_affected":"4.1.4"}],"source":"CPE_STRING"}}],"versions":["4.1.4","suricata-4.1.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-16411.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}