vendor:
Snort
by:
Marcin Zgorecki
5.5
CVSS
MEDIUM
Remote Denial of Service
399
CWE
Product Name: Snort
Affected Version From: 2.1.2003
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2005-0039
CPE: a:snort:snort
Platforms Tested:
2005
Snort Remote Denial of Service Vulnerability
The vulnerability exists in the DecodeTCPOptions() function of 'decode.c' in Snort. It is caused by a failure to handle malicious TCP packets properly. A remote attacker can exploit this vulnerability to crash a remote Snort server, preventing subsequent malicious attacks from being detected.
Mitigation:
Apply vendor patches or updates. Restrict network access to Snort servers.