Snort Multiple Denial Of Service Vulnerabilities
BID:36795
Info
Snort Multiple Denial Of Service Vulnerabilities
| Bugtraq ID: | 36795 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-3641 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2009 12:00AM |
| Updated: | Apr 13 2015 10:20PM |
| Credit: | Laurent Gaffié |
| Vulnerable: |
Snort Project Snort 2.8.5 |
| Not Vulnerable: |
Snort Project Snort 2.8.5.1 |
Discussion
Snort Multiple Denial Of Service Vulnerabilities
Snort is prone to multiple denial-of-service vulnerabilities because the application fails to properly process specially crafted IPv6 packets.
Attackers can exploit these issues to crash the affected application, causing denial-of-service conditions.
These issues affect Snort 2.8.5; other versions may also be vulnerable.
Snort is prone to multiple denial-of-service vulnerabilities because the application fails to properly process specially crafted IPv6 packets.
Attackers can exploit these issues to crash the affected application, causing denial-of-service conditions.
These issues affect Snort 2.8.5; other versions may also be vulnerable.
Exploit / POC
Snort Multiple Denial Of Service Vulnerabilities
Attackers can use readily available network utilities to exploit these issues.
The following exploits are available:
Attackers can use readily available network utilities to exploit these issues.
The following exploits are available:
Solution / Fix
Snort Multiple Denial Of Service Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Snort Multiple Denial Of Service Vulnerabilities
References:
References:
- Snort 2.8.5.1 Release (Snort Project)
- Snort Homepage (Snort Project)