Snort Buffer Overflow in DCE/RPC Preprocessor Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1017669
|
|
SecurityTracker URL: http://securitytracker.com/id?1017669
|
|
CVE Reference: CVE-2006-5276
(Links to External Site)
|
Date: Feb 20 2007
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Version(s): 2.6.1, 2.6.1.1, 2.6.1.2, 2.7.0 beta 1
|
Description: A vulnerability was reported in Snort in the DCE/RPC preprocessor. A remote user can execute arbitrary code on the target system.
A remote user can send specially crafted data to trigger a stack overflow and execute arbitrary code on the target system. The code
will run with the privileges of the target Snort service.
Sourcefire commercial products are also affected.
The vendor credits
Neel Mehta from IBM X-with reporting this vulnerability.
|
Impact: A remote user can execute arbitrary code on the target system.
|
Solution: The vendor has issued a fixed version (2.6.1.3).
The vendor plans to also issue a fix in version 2.7 beta 2.
The Snort advisory is available at:
http://www.snort.org/docs/advisory-2007-02-19.html
|
Vendor URL: www.snort.org/docs/advisory-2007-02-19.html (Links to External Site)
|
Cause: Boundary error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 19 Feb 2007 22:24:27 -0500
Subject: 2007-02-19 Sourcefire Advisory: Vulnerability in Snort DCE/RPC Preprocessor
|
http://www.snort.org/docs/advisory-2007-02-19.html
CVE-2006-5276
|
|