Gentoo: snort Multiple preprocessor vulnerabilities
Summary
- - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200304-06 - - ---------------------------------------------------------------------
- - ---------------------------------------------------------------------
New (and correct) ID and updated CVE link.
- From advisories:
"The Sourcefire Vulnerability Research Team has learned of an integer overflow in the Snort stream4 preprocessor used by the Sourcefire Network Sensor product line. The Snort stream4 preprocessor (spp_stream4) incorrectly calculates segment size parameters during stream reassembly for certain sequence number ranges which can lead to an integer overflow that can be expanded to a heap overflow.
The Snort stream4 flaw may lead to a denial of service (DoS) attack or remote command execution on a host running Snort. This attack can be launched by crafting TCP stream packets and transmitting them over a network segment that is being monitored by a vulnerable Snort...Read the Full Advisory
Resolution
References
Availability
Concerns
Background