CVE-2007-0251
Summary
| CVE | CVE-2007-0251 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-01-16 23:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files. |
Risk And Classification
Primary CVSS: v2.0 7.8 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityReason - Snort 2.6.1.2 Integer Underflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| osvdb.org/33464 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Just a moment... | af854a3a-2127-422b-91ae-364da2661108 | www.snort.org | |
| Snort GRE Packet Decoding Integer Underflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/32095 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| SecurityTracker.com Archives - Snort Integer Underflow in Processing the GRE Protocol May Let Remote Users Corrupt Log Files | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Calyptix Your Simple and Powerful Network Security Solution | af854a3a-2127-422b-91ae-364da2661108 | labs.calyptix.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.