vendor:
Snort
by:
KaiJern Lau
7.5
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: Snort
Affected Version From: 2.4.2000
Affected Version To: 2.4.2003
Patch Exists: YES
Related CWE: CVE-2005-3252
CPE: a:snort:snort
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2005
Snort Back Orifice Pre-Preprocessor Remote Exploit
This module exploits a stack overflow in the Back Orifice pre-processor module included with Snort versions 2.4.0, 2.4.1, 2.4.2, and 2.4.3. This vulnerability could be used to completely compromise a Snort sensor, and would typically gain an attacker full root or administrative privileges.
Mitigation:
Upgrade to the latest version of Snort