CVE-2018-18956 is a denial-of-service vulnerability affecting Suricata 4.x before 4.0.6, specifically within its SMTP parser. A remote attacker can exploit this flaw by sending crafted input, leading to a segfault and daemon crash. With a CVSS score of 7.5 (High), this vulnerability requires no user interaction and has a high impact on availability. While it was exploited in the wild in November 2018, there are no public exploit modules or significant community discussion, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.0.6CPE matchmatch criteria | cpe:2.3:a:suricata-ids:suricata:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.