Security Wire Digest - Information Security Magazine
CERT last week warned of two vulnerabilities in the Snort IDS that could allow attackers to execute arbitrary code and gain root privileges by sending malformed packets that result in a buffer overflow.
The vulnerabilities affect Snort Versions 1.8.x, 1.9.x, and 2.0 prior to RC1. For both vulnerabilities, attackers don't need to know the IP address of the Snort device they wish to attack. Instead, all that's needed is to send malicious traffic where it can be observed by an affected Snort sensor, according to the warning.
VU 139129 was found by members of Core Security Technologies, while members of ISS X-Force discovered VU 916785.
Upgrading to a newer version should remove the vulnerability. Sites that can't immediately upgrade may prevent exploitation by commenting out the affected preprocessor modules in the "snort.conf" configuration file.
CERT advisory
www.snort.org/dl/snort-2.0.0.tar.gz
http://www.coresecurity.com/content/snort-tcp-stre
ISS alert
Source: Security Wire Digest - Information Security Magazine
http://www.infosecuritymag.com/2003/apr/digest21.s











