CVE-2006-2769

The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sourcefire:snort:2.4:*:*:*:*:*:*:*
cpe:2.3:a:sourcefire:snort:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:sourcefire:snort:2.4.2:*:*:*:*:*:*:*
cpe:2.3:a:sourcefire:snort:2.4.3:*:*:*:*:*:*:*
cpe:2.3:a:sourcefire:snort:2.4.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-06-02 10:18

Updated : 2023-12-10 10:28


NVD link : CVE-2006-2769

Mitre link : CVE-2006-2769

CVE.ORG link : CVE-2006-2769


JSON object : View

Products Affected

sourcefire

  • snort
CWE
CWE-264

Permissions, Privileges, and Access Controls