|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
Snort contains a flaw that may allow a remote attacker to corrupt the IDS state and allow malicious activity to occur without detection. The issue is due to the stateful inspection engine not properly modifying the state of the established session. If an attacker sends a specially crafted malicious packet, they may trigger this condition which would allow subsequent traffic to be passed without detection.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
Snort
 |
2.0.0rc2 |
|
|
|
|
Credit |
- Evrim ULU - evrim
core.gen.tr -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|