PT-2008-3339 · Cisco · Snort

Published

2008-05-22

·

Updated

2017-08-08

·

CVE-2008-1804

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Snort versions prior to 2.8.1
Description The issue arises from improper identification of packet fragments with dissimilar TTL values in the preprocessors/spp frag3.c component. This allows remote attackers to bypass detection rules by using a different TTL for each fragment.
Recommendations For versions prior to 2.8.1, update to version 2.8.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2008-1804
DTSA-173-1

Affected Products

Snort