Snort Unified1 Output Remote Denial Of Service Vulnerability
BID:36473
Info
Snort Unified1 Output Remote Denial Of Service Vulnerability
| Bugtraq ID: | 36473 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2009 12:00AM |
| Updated: | Sep 22 2009 08:30PM |
| Credit: | Pablo Rincón Crespo |
| Vulnerable: |
Snort Project Snort 2.8.4 Snort Project Snort 2.8.3 Snort Project Snort 2.8.2 Snort Project Snort 2.8.1 |
| Not Vulnerable: |
Snort Project Snort 2.8.5 |
Discussion
Snort Unified1 Output Remote Denial Of Service Vulnerability
Snort is affected by a denial-of-service vulnerability because the application fails to properly process unified1 output.
Attackers can leverage this issue by sending malformed network packets that will produce corrupted logs and alerts, causing denial-of-service conditions.
Snort 2.8.1 through 2.8.4 are affected.
Snort is affected by a denial-of-service vulnerability because the application fails to properly process unified1 output.
Attackers can leverage this issue by sending malformed network packets that will produce corrupted logs and alerts, causing denial-of-service conditions.
Snort 2.8.1 through 2.8.4 are affected.
Exploit / POC
Snort Unified1 Output Remote Denial Of Service Vulnerability
Attackers can use readily available network utilities to exploit this issue.
The following exploit code is available:
Attackers can use readily available network utilities to exploit this issue.
The following exploit code is available:
Solution / Fix
Snort Unified1 Output Remote Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Snort Unified1 Output Remote Denial Of Service Vulnerability
References:
References:
- Snort ( 2.8.* < 2.8.5stable) Unified1 output bug (Pablo Rincón Crespo)
- Snort Homepage (Snort Project)