vendor:
Snort
by:
Winny Thomas
7.5
CVSS
HIGH
Remote code execution
CWE
Product Name: Snort
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2006-5276
CPE:
Platforms Tested: Red Hat Linux 8
2006
Snort DCE/RPC preprocessor vulnerability exploit
This exploit targets a vulnerability in the Snort DCE/RPC preprocessor, as described in CVE-2006-5276. It binds a shell to TCP port 4444 and connects to it. The exploit code was tested against snort-2.6.1 running on Red Hat Linux 8.
Mitigation:
Update to a patched version of Snort or disable the DCE/RPC preprocessor.