CVE-2007-1398

The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allows remote attackers to cause a denial of service (segmentation fault and application crash) via certain UDP packets produced by send_morefrag_packet and send_overlap_packet.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:linux:linux_kernel:*:*:ia32_64-bit:*:*:*:*:*
OR cpe:2.3:a:snort:snort:2.6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:snort:snort:2.6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:snort:snort:2.7_beta1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2007-03-10 22:19

Updated : 2023-12-10 10:40


NVD link : CVE-2007-1398

Mitre link : CVE-2007-1398

CVE.ORG link : CVE-2007-1398


JSON object : View

Products Affected

snort

  • snort

linux

  • linux_kernel