7.1
CVSSv2

CVE-2007-1398

Published: 10/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 715
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allows remote malicious users to cause a denial of service (segmentation fault and application crash) via certain UDP packets produced by send_morefrag_packet and send_overlap_packet.

Vulnerable Product Search on Vulmon Subscribe to Product

snort snort 2.6.1.1

snort snort 2.6.1.2

snort snort 2.7_beta1

Exploits

/********************************************************* * DOS Snort Inline * Affected Versions: 2611, 2612, 270(beta) * Requirements : Frag3 Enabled, Inline, Linux, ip_conntrack disabled * Antimatt3r * antimatter@gmailcom * Offset needs to be supplied that would cause reassembly for different snort * fragmentation reassembly pol ...