{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2019-10050","title":"Title"},{"category":"description","text":"A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-mpls.c function DecodeMPLS is composed only of a packet of source address and destination address plus the correct type field and the right number for shim, an attacker can manipulate the control flow, such that the condition to leave the loop is true. After leaving the loop, the network packet has a length of 2 bytes. There is no validation of this length. Later on, the code tries to read at an empty position, leading to a crash.","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2019-10050","url":"https://www.suse.com/security/cve/CVE-2019-10050"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1134991 for CVE-2019-10050","url":"https://bugzilla.suse.com/1134991"}],"title":"SUSE CVE CVE-2019-10050","tracking":{"current_release_date":"2025-07-28T23:43:59Z","generator":{"date":"2023-02-15T04:13:49Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2019-10050","initial_release_date":"2023-02-15T04:13:49Z","revision_history":[{"date":"2023-02-15T04:13:49Z","number":"2","summary":"Current version"},{"date":"2025-01-01T06:38:57Z","number":"3","summary":"Current version"},{"date":"2025-02-15T07:20:25Z","number":"4","summary":"Current version"},{"date":"2025-02-17T07:45:58Z","number":"5","summary":"Current version"},{"date":"2025-07-28T23:43:59Z","number":"6","summary":"Current version"}],"status":"interim","version":"6"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"openSUSE Tumbleweed","product":{"name":"openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed","product_identification_helper":{"cpe":"cpe:/o:opensuse:tumbleweed"}}},{"category":"product_version","name":"libsuricata8_0_0-8.0.0-1.1","product":{"name":"libsuricata8_0_0-8.0.0-1.1","product_id":"libsuricata8_0_0-8.0.0-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/libsuricata8_0_0@8.0.0-1.1"}}},{"category":"product_version","name":"suricata-8.0.0-1.1","product":{"name":"suricata-8.0.0-1.1","product_id":"suricata-8.0.0-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/suricata@8.0.0-1.1"}}},{"category":"product_version","name":"suricata-devel-8.0.0-1.1","product":{"name":"suricata-devel-8.0.0-1.1","product_id":"suricata-devel-8.0.0-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/suricata-devel@8.0.0-1.1"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"libsuricata8_0_0-8.0.0-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:libsuricata8_0_0-8.0.0-1.1"},"product_reference":"libsuricata8_0_0-8.0.0-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"suricata-8.0.0-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:suricata-8.0.0-1.1"},"product_reference":"suricata-8.0.0-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"suricata-devel-8.0.0-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:suricata-devel-8.0.0-1.1"},"product_reference":"suricata-devel-8.0.0-1.1","relates_to_product_reference":"openSUSE Tumbleweed"}]},"vulnerabilities":[{"cve":"CVE-2019-10050","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2019-10050"}],"notes":[{"category":"general","text":"A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-mpls.c function DecodeMPLS is composed only of a packet of source address and destination address plus the correct type field and the right number for shim, an attacker can manipulate the control flow, such that the condition to leave the loop is true. After leaving the loop, the network packet has a length of 2 bytes. There is no validation of this length. Later on, the code tries to read at an empty position, leading to a crash.","title":"CVE description"}],"product_status":{"recommended":["openSUSE Tumbleweed:libsuricata8_0_0-8.0.0-1.1","openSUSE Tumbleweed:suricata-8.0.0-1.1","openSUSE Tumbleweed:suricata-devel-8.0.0-1.1"]},"references":[{"category":"external","summary":"CVE-2019-10050","url":"https://www.suse.com/security/cve/CVE-2019-10050"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1134991 for CVE-2019-10050","url":"https://bugzilla.suse.com/1134991"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["openSUSE Tumbleweed:libsuricata8_0_0-8.0.0-1.1","openSUSE Tumbleweed:suricata-8.0.0-1.1","openSUSE Tumbleweed:suricata-devel-8.0.0-1.1"]}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.0"},"products":["openSUSE Tumbleweed:libsuricata8_0_0-8.0.0-1.1","openSUSE Tumbleweed:suricata-8.0.0-1.1","openSUSE Tumbleweed:suricata-devel-8.0.0-1.1"]}],"threats":[{"category":"impact","date":"2019-05-13T18:26:59Z","details":"moderate"}],"title":"CVE-2019-10050"}]}