Snort TCP Packet Reassembly Integer Overflow Vulnerability
BID:7178
Info
Snort TCP Packet Reassembly Integer Overflow Vulnerability
| Bugtraq ID: | 7178 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0209 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | Discovery of this issue is credited to Bruce Leidl, Juan Pablo Martinez Kuhn and Alejandro David Weil from Core Security Technologies. |
| Vulnerable: |
Snort Project Snort 1.9.1 Snort Project Snort 1.9 Snort Project Snort 1.8.7 Snort Project Snort 1.8.6 Snort Project Snort 1.8.5 Snort Project Snort 1.8.4 beta1 Snort Project Snort 1.8.4 Snort Project Snort 1.8.3 Snort Project Snort 1.8.2 Snort Project Snort 1.8.1 Snort Project Snort 1.8 SmoothWall SmoothWall 2.0 beta 4 |
| Not Vulnerable: |
Snort Project Snort 2.0 .0rc1 Snort Project Snort 2.0 |
Discussion
Snort TCP Packet Reassembly Integer Overflow Vulnerability
A vulnerability has been discovered in Snort. The problem occurs during the reassembly of TCP packets by the stream4 preprocesser. By sending specially crafted fragmented packets across a network monitored by Snort, it may be possible to trigger an integer overflow. As a result, a buffer overflow may occur, effectively allowing a remote attacker to corrupt heap memory.
Successful exploitation of this issue could allow a remote attacker to execute arbitrary code on a target system.
This issue effects Snort releases prior to Snort 2.0 RC1.
A vulnerability has been discovered in Snort. The problem occurs during the reassembly of TCP packets by the stream4 preprocesser. By sending specially crafted fragmented packets across a network monitored by Snort, it may be possible to trigger an integer overflow. As a result, a buffer overflow may occur, effectively allowing a remote attacker to corrupt heap memory.
Successful exploitation of this issue could allow a remote attacker to execute arbitrary code on a target system.
This issue effects Snort releases prior to Snort 2.0 RC1.
References
Snort TCP Packet Reassembly Integer Overflow Vulnerability
References:
References:
- Bug 2.0b4-mallard 005 (SmoothWall)
- CLSA-2003:671 (Conectiva)
- Snort Homepage (Snort Project)
- Snort TCP Stream Integer Overflow (CORE Security)
- Snort <=1.9.1 exploit (truff
)