Suricata IDS – IPv4 evasion

Posted by Jérémy BEAUME on Feb 15

Here are the details of the (patched) IPv4 evasion I found in Suricata IDS/IPS:

# Software
Suricata IDS/IPS
website : https://suricata-ids.org/
editor : Open Information Security Foundation (OISF) https://oisf.net/

# Impacted version

3.2.x before 3.2.13.13
3.1.3 and before

All execution mode are impacted : nfqueue, af-packet, …

# Vulnerability description

Suricata did not used the IP protocol field value to identify
fragments from a same…

Leave a Reply