PT-2006-3688 · Cisco · Snort

Christian Swartzbaugh

·

Publicado

2006-06-02

·

Atualizado

2018-10-18

·

CVE-2006-2769

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Snort versions 2.4.0 through 2.4.4
Description The issue allows remote attackers to bypass "uricontent" rules in the HTTP Inspect preprocessor. This can be achieved by inserting a carriage return (r) after the URL and before the HTTP declaration.
Recommendations For Snort versions 2.4.0 through 2.4.4, consider updating to a version that includes a fix for this issue, as no specific workaround is provided for these versions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-2769

Produtos afetados

Snort