CVE-2007-1398

The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allows remote attackers to cause a denial of service (segmentation fault and application crash) via certain UDP packets produced by send_morefrag_packet and send_overlap_packet.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:linux:linux_kernel:*:*:ia32_64-bit:*:*:*:*:*
OR cpe:2.3:a:snort:snort:2.6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:snort:snort:2.6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:snort:snort:2.7_beta1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:28

Type Values Removed Values Added
References () http://www.osvdb.org/33024 - () http://www.osvdb.org/33024 -
References () http://www.securityfocus.com/bid/22872 - () http://www.securityfocus.com/bid/22872 -
References () http://www.snort.org/docs/release_notes/release_notes_2613.txt - () http://www.snort.org/docs/release_notes/release_notes_2613.txt -
References () https://www.exploit-db.com/exploits/3434 - () https://www.exploit-db.com/exploits/3434 -

Information

Published : 2007-03-10 22:19

Updated : 2024-11-21 00:28


NVD link : CVE-2007-1398

Mitre link : CVE-2007-1398

CVE.ORG link : CVE-2007-1398


JSON object : View

Products Affected

linux

  • linux_kernel

snort

  • snort