Описание
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.
Ссылки
- PatchVendor Advisory
- ExploitPatch
- ExploitVendor Advisory
- Exploit
- Exploit
- Exploit
- PatchVendor Advisory
- ExploitPatch
- ExploitVendor Advisory
- Exploit
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sourcefire:snort:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:sourcefire:snort:2.1.1_rc1:*:*:*:*:*:*:*
cpe:2.3:a:sourcefire:snort:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:sourcefire:snort:2.2:*:*:*:*:*:*:*
EPSS
Процентиль: 96%
0.22655
Средний
7.8 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
debian
больше 20 лет назад
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when ...
github
больше 3 лет назад
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.
EPSS
Процентиль: 96%
0.22655
Средний
7.8 High
CVSS2
Дефекты
NVD-CWE-Other