Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
87

Debian - DSA-5354-1 Critical: Snort DoS Attack Mitigation

Multiple security vulnerabilities were discovered in snort, a flexible Network Intrusion Detection System, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or bypass filtering technology on an affected device and ex-filtrate data from a compromised host. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5354-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany February 18, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : snort CVE ID : CVE-2020-3299 CVE-2020-3315 CVE-2021-1223 CVE-2021-1224 CVE-2021-1236 CVE-2021-1494 CVE-2021-1495 CVE-2021-34749 CVE-2021-40114 Debian Bug : 1021276 Multiple security vulnerabilities were discovered in snort, a flexible Network Intrusion Detection System, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or bypass filtering technology on an affected device and ex-filtrate data from a compromised host. For the stable distribution (bullseye), these problems have been fixed in version 2.9.20-0+deb11u1. We recommend that you upgrade your snort packages. For the detailed security status of snort please refer to its security tracker page at: Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Numerous security flaws identified in Suricata; immediate upgrade advised to reduce threats and strengthen protection.. Snort Security Update, Debian DSA, Network Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 18, 2023 Critical Debian
197

Debian 10 DLA-3317-1: Snort DoS Threats and Security Fix

Multiple security vulnerabilities were discovered in snort, a flexible Network Intrusion Detection System, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or bypass filtering technology on an affected device and ex-filtrate data from a compromised host. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3317-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany February 11, 2023 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : snort Version : 2.9.20-0+deb10u1 CVE ID : CVE-2020-3299 CVE-2020-3315 CVE-2021-1223 CVE-2021-1224 CVE-2021-1236 CVE-2021-1494 CVE-2021-1495 CVE-2021-34749 CVE-2021-40114 Debian Bug : 1021276 Multiple security vulnerabilities were discovered in snort, a flexible Network Intrusion Detection System, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or bypass filtering technology on an affected device and ex-filtrate data from a compromised host. For Debian 10 buster, these problems have been fixed in version 2.9.20-0+deb10u1. We recommend that you upgrade your snort packages. For the detailed security status of snort please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Tackling numerous weaknesses found in Snort for Debian LTS, emphasizing severe DoS threats and potential evasion techniques in filtering.. Snort Security Update, Debian LTS, DoS Threat, Intrusion Detection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 10, 2023 Critical Debian LTS
89

Fedora 11 Snort Update FEDORA-2009-10783 Critical: DoS IPv6 Packet Crash

Update to 2.8.5.1 which includes a fix for CVE-2009-3641 DoS (crash) while printing specially-crafted IPv6 packet using the -v option. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-10783 2009-10-27 05:01:41 -------------------------------------------------------------------------------- Name : snort Product : Fedora 11 Version : 2.8.5.1 Release : 1.fc11 URL : https://www.snort.org/ Summary : Intrusion detection system Description : Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging and can perform protocol analysis, content searching/matching and can be used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, OS fingerprinting attempts, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog, a separate "alert" file, or as a WinPopup message via Samba's smbclient Edit /etc/snort.conf to configure snort and use snort.d to start snort This rpm is different from previous rpms and while it will not clobber your current snortd file, you will need to modify it. There are 9 different packages available All of them require the base snort rpm. Additionally, you will need to chose a binary to install. /usr/sbin/snort should end up being a symlink to a binary in one of the following configurations: plain plain+flexresp mysql mysql+flexresp postgresql postgresql+flexresp snmp snmp+flexresp bloat mysql+postgresql+flexresp+snmp Please see the documentation in /usr/share/doc/snort-2.8.5.1 There are no rules in this package the license they are released under forbids us from repackaging them and redistributing them. -------------------------------------------------------------------------------- Update Information: Update to 2.8.5.1 which includes a fix for CVE-2009-3641 DoS (crash)while printing specially-crafted IPv6 packet using the -v option -------------------------------------------------------------------------------- ChangeLog: * Sun Oct 25 2009 Dennis Gilmore - 2.8.5.1-1 - update for CVE-2009-3641 * Sun Jul 26 2009 Fedora Release Engineering - 2.8.3.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Sun Apr 19 2009 Robert Scheck - 2.8.3.2-3 - Build require package libnet10-devel rather libnet10 -------------------------------------------------------------------------------- References: [ 1 ] Bug #530863 - CVE-2009-3641 Snort: DoS (crash) while printing specially-crafted IPv6 packet using the -v option https://bugzilla.redhat.com/show_bug.cgi?id=530863 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update snort' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The Dnsmasq 2.79 patch addresses the DoS flaw CVE-2020-25681 in Ubuntu 20.04 for enhanced protection and reliability.. Fedora Snort DoS Patch Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 24, 2009 Critical Fedora
89

Fedora 11: FEDORA-2009-10999 Important: OpenSSH Vulnerability Patch

Update to 2.8.5.1 which includes a fix for CVE-2009-3641 DoS (crash) while printing specially-crafted IPv6 packet using the -v option. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-10751 2009-10-27 05:00:33 -------------------------------------------------------------------------------- Name : snort Product : Fedora 10 Version : 2.8.5.1 Release : 1.fc10 URL : https://www.snort.org/ Summary : Intrusion detection system Description : Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging and can perform protocol analysis, content searching/matching and can be used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, OS fingerprinting attempts, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog, a separate "alert" file, or as a WinPopup message via Samba's smbclient Edit /etc/snort.conf to configure snort and use snort.d to start snort This rpm is different from previous rpms and while it will not clobber your current snortd file, you will need to modify it. There are 9 different packages available All of them require the base snort rpm. Additionally, you will need to chose a binary to install. /usr/sbin/snort should end up being a symlink to a binary in one of the following configurations: plain plain+flexresp mysql mysql+flexresp postgresql postgresql+flexresp snmp snmp+flexresp bloat mysql+postgresql+flexresp+snmp Please see the documentation in /usr/share/doc/snort-2.8.5.1 There are no rules in this package the license they are released under forbids us from repackaging them and redistributing them. -------------------------------------------------------------------------------- Update Information: Update to 2.8.5.1 which includes a fix for CVE-2009-3641 DoS (crash)while printing specially-crafted IPv6 packet using the -v option -------------------------------------------------------------------------------- ChangeLog: * Sun Oct 25 2009 Dennis Gilmore - 2.8.5.1-1 - update for CVE-2009-3641 * Sun Jul 26 2009 Fedora Release Engineering - 2.8.3.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Sun Apr 19 2009 Robert Scheck - 2.8.3.2-3 - Build require package libnet10-devel rather libnet10 * Wed Feb 25 2009 Fedora Release Engineering - 2.8.3.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Mon Feb 16 2009 Dennis Gilmore - 2.8.3.2-1 - update to 2.8.3.2 * Fri Jan 23 2009 Dennis Gilmore - 2.8.1-6 - rebuild for new mysql -------------------------------------------------------------------------------- References: [ 1 ] Bug #530863 - CVE-2009-3641 Snort: DoS (crash) while printing specially-crafted IPv6 packet using the -v option https://bugzilla.redhat.com/show_bug.cgi?id=530863 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update snort' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Essential Fedora patch for snort addressing a DoS vulnerability linked to IPv6 packet processing in release 2.8.5.1.. snort Security,Fedora Updates,IPv6 DoS Fix,Network Intrusion Protection. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 24, 2009 Important Fedora
91

Gentoo: GLSA-200702-03 Normal Severity: Snort Denial of Service

Snort contains a vulnerability in the rule matching algorithm that could result in a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200702-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Snort: Denial of Service Date: February 13, 2007 Bugs: #161632 ID: 200702-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Snort contains a vulnerability in the rule matching algorithm that could result in a Denial of Service. Background ========= Snort is a widely deployed intrusion detection program. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/snort < 2.6.1.2 > = 2.6.1.2 Description ========== Randy Smith, Christian Estan and Somesh Jha discovered that the rule matching algorithm of Snort can be exploited in a way known as a "backtracking attack" to perform numerous time-consuming operations. Impact ===== A remote attacker could send specially crafted network packets, which would result in the cessation of the detections and the consumption of the CPU resources. Workaround ========= There is no known workaround at this time. Resolution ========= All Snort users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-analyzer/snort-2.6.1.2" References ========= [ 1 ] CVE-2006-6931 https://www.cve.org/CVERecord?id=CVE-2006-6931 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200702-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo alert highlights Snort's vulnerability to Denial of Service attacks linked to rule matching deficiencies; users advised to update.. Snort Vulnerability, Denial of Service, Gentoo Advisory. . LinuxSecurity.com Team

Calendar%202 Feb 13, 2007 Gentoo
87

Debian: DSA-297-1 Critical: Snort Buffer Overflow Remote Exploit

Two vulnerabilities have been discoverd in Snort.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 297-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze May 1st, 2003 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : snort Vulnerability : integer overflow, buffer overflow Problem-Type : remote Debian-specific: no CVE Ids : CAN-2003-0033 CAN-2003-0209 CERT advisories: VU#139129 VU#916785 Bugtraq Ids : 7178 6963 Two vulnerabilities have been discoverd in Snort, a popular network intrusion detection system. Snort comes with modules and plugins that perform a variety of functions such as protocol analysis. The following issues have been identified: Heap overflow in Snort "stream4" preprocessor (VU#139129, CAN-2003-0209, Bugtraq Id 7178) Researchers at CORE Security Technologies have discovered a remotely exploitable inteter overflow that results in overwriting the heap in the "stream4" preprocessor module. This module allows Snort to reassemble TCP packet fragments for further analysis. An attacker could insert arbitrary code that would be executed as the user running Snort, probably root. Buffer overflow in Snort RPC preprocessor (VU#916785, CAN-2003-0033, Bugtraq Id 6963) Researchers at Internet Security Systems X-Force have discovered a remotely exploitable buffer overflow in the Snort RPC preprocessor module. Snort incorrectly checks the lengths of what is being normalized against the current packet size. An attacker could exploit this to execute arbitrary code under the privileges of the Snort process, probably root. For the stable distribution (woody) these problems have been fixed in version 1.8.4beta1-3.1. The old stable distribution (potato) is not affected by these problems since it doesn't contain theproblematic code. For the unstable distribution (sid) these problems have been fixed in version 2.0.0-1. We recommend that you upgrade your snort package immediately. You are also advised to upgrade to the most recent version of Snort, since Snort, as any intrusion detection system, is rather useless if it is based on old and out-dated data and not kept up to date. Such installations would be unable to detect intrusions using modern methods. The current version of Snort is 2.0.0, while the version in the stable distribution (1.8) is quite old and the one in the old stable distribution is beyond hope. Since Debian does not update arbitrary packages in stable releases, even Snort is not going to see updates other than to fix security problems, you are advised to upgrade to the most recent version from third party sources. The Debian maintainer for Snort provides backported up-to-date packages for woody (stable) and potato (oldstable) for cases where you cannot upgrade your entire system. These packages are untested, though and only exist for the i386 architecture: deb ./ deb-src ./ deb ./ deb-src ./ Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 681 2186ab4fe2efad905f07fb9522f04597 Size/MD5 checksum: 67265 1f8ea5bc8a842626a30a2fb693398a16 Size/MD5 checksum: 1718574 80201d9c4e33af5e0b56121e4f9f7f7b Architecture independent components: Size/MD5 checksum: 344358 5d15c2a2ffc2e085a4dacfc8226ba336 Size/MD5 checksum: 59674 76c3416b6a5e97c4b82e984255ee62a6 Alpha architecture: Size/MD5 checksum: 218862 e289d2ac6a97c3c729575af2608d62da Size/MD5 checksum: 35798 7d1a116fc1c00006914e48019ba68a4b Size/MD5 checksum: 222492 589db8d591013c098a4d51981464b21e ARM architecture: Size/MD5 checksum: 178156 f37eb2c6b75176be30aaae92cfd699ea Size/MD5 checksum: 35820 4977d033364e56ec0d66266918b5ddfb Size/MD5 checksum: 181128 d7d40fc33fd3e51b54e4293ed7617c70 Intel IA-32 architecture: Size/MD5 checksum: 162048 f26f7562fae5f8761834d4cabe3ed17c Size/MD5 checksum: 35802 548afa7fde8557dcd40bf235f38074dc Size/MD5 checksum: 165354 911fd22a147390c8cf5d4694b4e2b18b Intel IA-64 architecture: Size/MD5 checksum: 271778 12be6ab4ac58909148a8c9625ebefb99 Size/MD5 checksum: 35798 57f0772e114cc1130c5c2639fc64be71 Size/MD5 checksum: 275284 a8489c8f41fa49d532c0afa67928ee61 HP Precision architecture: Size/MD5 checksum: 201916 91c8ee56127b14c92736d7d418bc05ca Size/MD5 checksum: 35816 a5718f767ebc93178eb820dc5a190579 Size/MD5 checksum: 205334 00eb158e0b034dbb6e16e42223f5855b Motorola 680x0 architecture: Size/MD5 checksum: 150320 3c205732845c14274bd9d8520f8ba806 Size/MD5 checksum: 35850 3b8e1da42a9c796a0ecf74f1e7ca2ac1 Size/MD5 checksum: 153552 f97f6f155c93f042f01a9f2e40aff91d Big endian MIPS architecture: Size/MD5 checksum: 198172 75e4fef830c00e952f05cf4139bc264f Size/MD5 checksum: 35822 aadad43bcef00f74acc754302e3557fc Size/MD5 checksum: 201404 9fa10daa290890849df6762b66825024 Little endian MIPS architecture: Size/MD5 checksum: 199732 040b188aeb253aa4ec4a6903c3f6f792 Size/MD5 checksum: 35818 467f455bb8b2c59630470417673e9856 Size/MD5 checksum: 202972755df8c2d9b7e2bc01fec9a0b2259f4d PowerPC architecture: Size/MD5 checksum: 174508 3b5d1ebec2d40949e49746b4365c0a81 Size/MD5 checksum: 35804 60575d5c1998634b6bb3d2a9696f95c6 Size/MD5 checksum: 177562 c8cdeaab4e7c41c01a435933103fe6dd IBM S/390 architecture: Size/MD5 checksum: 173002 ff71b2925e1020c278d7d33eed8f8e6d Size/MD5 checksum: 35794 5207eb80204af25cdbd77dca4b6cc09e Size/MD5 checksum: 176296 2cc04f18ee550e4595e1680b43c2bf3e Sun Sparc architecture: Size/MD5 checksum: 176202 6f1325e6c45e06d3f769b18a9ce98274 Size/MD5 checksum: 35806 91ada09e5b9386b803184417ecbd953c Size/MD5 checksum: 179444 deb6b8580ef04cabecfec3972f4519dd These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Critical vulnerabilities discovered in Snort on Debian prompt immediate package upgrades.. Debian Snort Update, Critical Alerts, Package Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 01, 2003 Critical Debian
91

Gentoo: 200304-06 Critical Advisory on Snort Buffer Overflow and DoS

The Snort stream4 preprocessor (spp_stream4) incorrectlycalculates segment size parameters during stream reassembly for certainsequence number ranges which can lead to an integer overflow that can beexpanded to a heap overflow.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200304-06 - - --------------------------------------------------------------------- PACKAGE : snort SUMMARY : Multiple Vulnerabilities in Snort Preprocessors DATE : 2003-04-28 07:07 UTC EXPLOIT : remote VERSIONS AFFECTED : =snort-2.0.0 CVE : CAN-2003-0209 CAN-2003-0033 - - --------------------------------------------------------------------- New (and correct) ID and updated CVE link. - From advisories: "The Sourcefire Vulnerability Research Team has learned of an integer overflow in the Snort stream4 preprocessor used by the Sourcefire Network Sensor product line. The Snort stream4 preprocessor (spp_stream4) incorrectly calculates segment size parameters during stream reassembly for certain sequence number ranges which can lead to an integer overflow that can be expanded to a heap overflow. The Snort stream4 flaw may lead to a denial of service (DoS) attack or remote command execution on a host running Snort. This attack can be launched by crafting TCP stream packets and transmitting them over a network segment that is being monitored by a vulnerable Snort implementation. In its default configuration, certain versions of snort are vulnerable to this attack, as is the default configuration of the Snort IDS." "Remote attackers may exploit the buffer overflow condition to run arbitrary code on a Snort sensor with the privileges of the Snort IDS process, which typically runs as the superuser. The vulnerable preprocessor is enabled by default. It is not necessary to establish an actual connection to a RPC portmapper service to exploit this vulnerability." Read the full advisories at: ;idxseccion=10 SOLUTION Itis recommended that all Gentoo Linux users who are running net-analyzer/snort upgrade to snort-2.0.0 as follows: emerge sync emerge snort emerge clean . Gentoo Linux alerts users to significant security flaws in Snort's Stream4 preprocessor, applicable to all releases before 2.9.18, recommending urgent updates to avert potential threats.. Snort Vulnerabilities, Gentoo Security Update, Stream4 Preprocessor Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 28, 2003 Critical Gentoo
91

Gentoo: 200303-6.1 Critical: Snort Buffer Overflow Threat

Remote attackers may exploit the buffer overflow condition to run arbitrary code on a Snort sensor with the privileges of the Snort IDS process, which typically runs as the superuser.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200303-6.1 - - --------------------------------------------------------------------- PACKAGE : snort SUMMARY : buffer overflow DATE : 2003-03-06 10:59 UTC EXPLOIT : remote VERSIONS AFFECTED : 1.9.1 CVE : CAN-2003-0033 - - --------------------------------------------------------------------- - From advisory: "Remote attackers may exploit the buffer overflow condition to run arbitrary code on a Snort sensor with the privileges of the Snort IDS process, which typically runs as the superuser. The vulnerable preprocessor is enabled by default. It is not necessary to establish an actual connection to a RPC portmapper service to exploit this vulnerability." Read the full advisory at: SOLUTION It is recommended that all Gentoo Linux users who are running net-analyzer/snort upgrade to snort-1.9.1 as follows: emerge sync emerge -u snort emerge clean - - --------------------------------------------------------------------- This email address is being protected from spambots. You need JavaScript enabled to view it. - GnuPG key is available at - - --------------------------------------------------------------------- . Gentoo Linux identifies significant security vulnerability in Snort. Urgent patch advised to mitigate risks of attacks.. buffer overflow, snort exploit, remote access, gentoo security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 07, 2003 Critical Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200