PT-2006-1886 · Sourcefire · Sourcefire Snort
Published
2006-02-22
·
Updated
2018-10-18
·
CVE-2006-0839
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Sourcefire Snort version 2.4.3
Description
The issue is related to the frag3 preprocessor, which does not properly reassemble certain fragmented packets with IP options. This allows remote attackers to evade detection of certain attacks, possibly related to IP option lengths.
Recommendations
For Sourcefire Snort version 2.4.3, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sourcefire Snort