Network box
There are two vulnerabilities in the Snort Intrusion Detection System, each in a separate preprocessor module. Both vulnerabilities allow remote attackers to execute arbitrary code with the privileges of the user running Snort, typically root.
The Snort intrusion detection system ships with a variety of preprocessor modules that allow the user to selectively include additional functionality. Researchers from two independent organizations have discovered vulnerabilities in two of these modules, the RPC preprocessor and the "stream4" TCP fragment reassembly preprocessor.
For additional information regarding Snort, please see
VU#139129 - Heap overflow in Snort "stream4" preprocessor (CAN-2003-0029)
Researchers at CORE Security Technologies have discovered a remotely exploitable heap overflow in the Snort "stream4" preprocessor module. This module allows Snort to reassemble TCP packet fragments for further analysis.
To exploit this vulnerability, an attacker must disrupt the state tracking mechanism of the preprocessor module by sending a series of packets with crafted sequence numbers. This causes the module to bypass a check for buffer overflow attempts and allows the attacker to insert arbitrary code into the heap.
For additional information, please read the Core Security Technologies Advisory located at
http://www.coresecurity.com/content/snort-tcp-stre
This vulnerability affects Snort versions 1.8.x, 1.9.x, and 2.0 prior to RC1. Snort has published an advisory regarding this vulnerability; it is available at
http://www.snort.org/advisories/snort-2003-04-16-1
VU#916785 - Buffer overflow in Snort RPC preprocessor (CAN-2003-0033)
Researchers at Internet Security Systems (ISS) have discovered a remotely exploitable buffer overflow in the Snort RPC preprocessor module. Martin Roesch, primary developer for Snort, described the vulnerability as follows:
When the RPC decoder normalizes fragmented RPC records, it incorrectly checks the lengths of what is being normalized against the current packet size, leading to an overflow condition. The RPC preprocessor is enabled by default.
For additional information, please read the ISS X-Force advisory located at
http://www.iss.net/issEn/delivery/xforce/alertdeta
This vulnerability affects Snort versions 1.8.x through 1.9.1 and version 2.0 Beta.
Source: Network Box Corporation
http://www.network-box.com/?keywords=home:news&











