7.8
CVSSv2

CVE-2004-2652

Published: 31/12/2004 Updated: 20/07/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 790
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The DecodeTCPOptions function in decode.c in Snort prior to 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote malicious users to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

sourcefire snort 2.1.0

sourcefire snort 2.1.1_rc1

sourcefire snort 2.1.3

sourcefire snort 2.2

Exploits

source: wwwsecurityfocuscom/bid/12084/info Snort is reported prone to a remote denial of service vulnerability The vulnerability is reported to exist in the DecodeTCPOptions() function of 'decodec', and is as a result of a failure to sufficiently handle malicious TCP packets A remote attacker may trigger this vulnerability to crash ...
source: wwwsecurityfocuscom/bid/12084/info Snort is reported prone to a remote denial of service vulnerability The vulnerability is reported to exist in the DecodeTCPOptions() function of 'decodec', and is as a result of a failure to sufficiently handle malicious TCP packets A remote attacker may trigger this vulnerability to crash a ...