CVE-2007-1398 Information

Description

The frag3 preprocessor in Snort 2.6.1.1 2.6.1.2 and 2.7.0 beta when configured for inline use on Linux without the ip_conntrack module loaded allows remote attackers to cause a denial of service (segmentation fault and application crash) via certain UDP packets produced by send_morefrag_packet and send_overlap_packet.

Reference

http://www.osvdb.org/33024 http://www.securityfocus.com/bid/22872 http://www.snort.org/docs/release_notes/release_notes_2613.txt https://www.exploit-db.com/exploits/3434

Share on: