5
CVSSv2

CVE-2006-2769

Published: 02/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 up to and including 2.4.4 allows remote malicious users to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration.

Vulnerable Product Search on Vulmon Subscribe to Product

sourcefire snort 2.4.4

sourcefire snort 2.4

sourcefire snort 2.4.1

sourcefire snort 2.4.2

sourcefire snort 2.4.3

Vendor Advisories

Debian Bug report logs - #381726 CVE-2006-2769: HTTP Inspect preprocessor evasion Package: snort; Maintainer for snort is Javier Fernández-Sanguino Peña <jfs@debianorg>; Source for snort is src:snort (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Sun, 6 Aug 2006 20:03:09 UTC Severity: n ...

Exploits

source: wwwsecurityfocuscom/bid/18200/info Snort is reportedly prone to a vulnerability that may allow malicious packets to bypass detection A successful attack can allow attackers to bypass intrusion detection and to carry out attacks against computers protected by Snort This vulnerability affects Snort 244 Other versions may be ...