Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-0839

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2006-0839
Last Modified 05 Sep 2008 05:00:21
Published 21 Feb 2006 09:02:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-0839

Summary

The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remote attackers to evade detection of certain attacks, possibly related to IP option lengths.

Vulnerable Systems

Application

  • Sourcefire Snort 2.4.3


References

BID - 16705

BUGTRAQ - 20060217 SNORT Incorrect fragmented packet reassembly

SECUNIA - 18959

XF - snort-frag3-detection-bypass(24811)


Last Updated: 27 May 2016 10:41:49