Snort PrintTcpOptions Remote Denial Of Service Vulnerability
BID:14811
Info
Snort PrintTcpOptions Remote Denial Of Service Vulnerability
| Bugtraq ID: | 14811 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2005 12:00AM |
| Updated: | Sep 12 2005 12:00AM |
| Credit: | "A. Alejandro Hernandez" <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Snort Project Snort 2.4 .0 Snort Project Snort 2.3.3 Snort Project Snort 2.3.2 Snort Project Snort 2.3.1 Snort Project Snort 2.3 .0 Snort Project Snort 2.2 Snort Project Snort 2.1.3 Snort Project Snort 2.1.1 RC1 Snort Project Snort 2.1 .0 Snort Project Snort 2.0.6 Snort Project Snort 2.0.4 Snort Project Snort 2.0 rc2 Snort Project Snort 2.0 .0rc1 Snort Project Snort 2.0 |
| Not Vulnerable: | |
Discussion
Snort PrintTcpOptions Remote Denial Of Service Vulnerability
Snort is reported prone to a remote denial of service vulnerability. The vulnerability is reported to exist in the 'PrintTcpOptions()' function of 'log.c', and is a result of a failure to sufficiently handle malicious TCP packets.
A remote attacker may trigger this vulnerability to crash a remote Snort server and in doing so may prevent subsequent malicious attacks from being detected.
It should be noted that the vulnerable code path is only executed when Snort is run with the '-v' (verbose) flag. Due to the performance penalty of running the Snort application in verbose mode, it is likely that most production installations of the application are not vulnerable to this issue.
Update: Further messages have stated that other paths to the vulnerable code may be possible. Using the 'frag3' preprocessor, ASCII mode logging, the '-A fast' command-line option, and possibly other options may expose Snort to this vulnerability. Please see the referenced messages for further information.
Snort is reported prone to a remote denial of service vulnerability. The vulnerability is reported to exist in the 'PrintTcpOptions()' function of 'log.c', and is a result of a failure to sufficiently handle malicious TCP packets.
A remote attacker may trigger this vulnerability to crash a remote Snort server and in doing so may prevent subsequent malicious attacks from being detected.
It should be noted that the vulnerable code path is only executed when Snort is run with the '-v' (verbose) flag. Due to the performance penalty of running the Snort application in verbose mode, it is likely that most production installations of the application are not vulnerable to this issue.
Update: Further messages have stated that other paths to the vulnerable code may be possible. Using the 'frag3' preprocessor, ASCII mode logging, the '-A fast' command-line option, and possibly other options may expose Snort to this vulnerability. Please see the referenced messages for further information.
Exploit / POC
Snort PrintTcpOptions Remote Denial Of Service Vulnerability
The following proof of concept exploit is available:
The following proof of concept exploit is available:
Solution / Fix
Snort PrintTcpOptions Remote Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Snort PrintTcpOptions Remote Denial Of Service Vulnerability
References:
References:
- Re: [Snort-users] Snort DoS Fallacies (Martin Roesch
) - Snort DoS Fallacies ("Ferguson, Justin (IARC)"
) - Snort Homepage (Snort Project)
- Snort <= 2.4.0 SACK TCP Option Error Handling ("A. Alejandro Hernandez"
)