LWN.net Logo

snort: detection rules bypass

Package(s):snort CVE #(s):CVE-2008-1804
Created:June 6, 2008 Updated:December 11, 2009
Description: From the CVE entry: preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, which allows remote attackers to bypass detection rules by using a different TTL for each fragment.
Alerts:
Mandriva MDVSA-2009:259-1 2009-12-11
Mandriva MDVSA-2009:259 2009-10-07
Fedora FEDORA-2008-5045 2008-06-06
Fedora FEDORA-2008-5001 2008-06-06
Fedora FEDORA-2008-4986 2008-06-06

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds