Snort Spoofed Packet TCP State Evasion Vulnerability
BID:7635
Info
Snort Spoofed Packet TCP State Evasion Vulnerability
| Bugtraq ID: | 7635 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2003 12:00AM |
| Updated: | May 20 2003 12:00AM |
| Credit: | This vulnerability was reported by Evrim ULU <[email protected]>. |
| Vulnerable: |
Snort Project Snort 2.0 rc2 |
| Not Vulnerable: | |
Discussion
Snort Spoofed Packet TCP State Evasion Vulnerability
A vulnerability has been reported for Snort 2.0.0rc2. The problem lies in the stateful inspection maintained by Snort. A malicious spoofed packet may trigger an incorrect modification to the state of the established session. Reportedly, this may result in further legitimate session traffic going undetected.
This issue could be exploited by an attacker to establish a legitimate session and corrupt the state, effectively allowing for malicious network activity to be transmitted without detection.
A vulnerability has been reported for Snort 2.0.0rc2. The problem lies in the stateful inspection maintained by Snort. A malicious spoofed packet may trigger an incorrect modification to the state of the established session. Reportedly, this may result in further legitimate session traffic going undetected.
This issue could be exploited by an attacker to establish a legitimate session and corrupt the state, effectively allowing for malicious network activity to be transmitted without detection.
Exploit / POC
Snort Spoofed Packet TCP State Evasion Vulnerability
This issue can be exploited with any number of packet crafting tools.
This issue can be exploited with any number of packet crafting tools.
Solution / Fix
Snort Spoofed Packet TCP State Evasion Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.