This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Snort vuln - update available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.snort.org/docs/advisory-2007-02-19.html
2007-02-19
"Summary: Sourcefire has learned of a remotely exploitable vulnerability in the Snort DCE/RPC preprocessor. This preprocessor is vulnerable to a stack-based buffer overflow that could potentially allow attackers to execute code with the same privileges as the Snort binary. Sourcefire has prepared updates for Snort open-source software to address this…
Snort Versions Affected:
* Snort 2.6.1, [removed], and [removed]
* Snort 2.7.0 beta 1
This vulnerability also affects Sourcefire commercial products. For information and updates for Sourcefire products, please go to the Sourcefire support site.
Mitigating Factors:
Users who have disabled the DCE/RPC preprocessor are not vulnerable. However, the DCE/RPC preprocessor is enabled by default.
Recommended Actions:
* Open-source Snort 2.6.1.x users are advised to upgrade to Snort 2.6.1.3* (or later) immediately.
* Open-source Snort 2.7 beta users are advised to mitigate this issue by disabling the DCE/RPC preprocessor. This issue will be resolved in Snort 2.7 beta 2…"

* http://www.snort.org/dl/

Release notes:
http://www.snort.org/docs/release_notes/re…_notes_2613.txt

.