Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple security vulnerabilities were discovered in snort, a flexible Network Intrusion Detection System, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or bypass filtering technology on an affected device and ex-filtrate data from a compromised host. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5354-1
Multiple security vulnerabilities were discovered in snort, a flexible Network Intrusion Detection System, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or bypass filtering technology on an affected device and ex-filtrate data from a compromised host. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3317-1
Update to 2.8.5.1 which includes a fix for CVE-2009-3641 DoS (crash) while printing specially-crafted IPv6 packet using the -v option. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-10783 2009-10-27 05:01:41 -------------------------------------------------------------------------------- Name : snort Product : Fedora 11 Version : 2.8.5.1 Release : 1.fc11 URL : https://www.snort.org/ Summary : Intrusion detection system Description : Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging and can perform protocol analysis, content searching/matching and can be used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, OS fingerprinting attempts, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog, a separate "alert" file, or as a WinPopup message via Samba's smbclient Edit /etc/snort.conf to configure snort and use snort.d to start snort This rpm is different from previous rpms and while it will not clobber your current snortd file, you will need to modify it. There are 9 different packages available All of them require the base snort rpm. Additionally, you will need to chose a binary to install. /usr/sbin/snort should end up being a symlink to a binary in one of the following configurations: plain plain+flexresp mysql mysql+flexresp postgresql postgresql+flexresp snmp snmp+flexresp bloat mysql+postgresql+flexresp+snmp Please see the documentation in /usr/share/doc/snort-2.8.5.1 There are no rules in this package the license they are released under forbids us from repackaging them and redistributing them. -------------------------------------------------------------------------------- Update Information: Update to 2.8.5.1 which includes a fix for CVE-2009-3641 DoS (crash)while printing specially-crafted IPv6 packet using the -v option -------------------------------------------------------------------------------- ChangeLog: * Sun Oct 25 2009 Dennis Gilmore - 2.8.5.1-1 - update for CVE-2009-3641 * Sun Jul 26 2009 Fedora Release Engineering - 2.8.3.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Sun Apr 19 2009 Robert Scheck - 2.8.3.2-3 - Build require package libnet10-devel rather libnet10 -------------------------------------------------------------------------------- References: [ 1 ] Bug #530863 - CVE-2009-3641 Snort: DoS (crash) while printing specially-crafted IPv6 packet using the -v option https://bugzilla.redhat.com/show_bug.cgi?id=530863 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update snort' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Update to 2.8.5.1 which includes a fix for CVE-2009-3641 DoS (crash) while printing specially-crafted IPv6 packet using the -v option. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-10751 2009-10-27 05:00:33 -------------------------------------------------------------------------------- Name : snort Product : Fedora 10 Version : 2.8.5.1 Release : 1.fc10 URL : https://www.snort.org/ Summary : Intrusion detection system Description : Snort is a libpcap-based packet sniffer/logger which can be used as a lightweight network intrusion detection system. It features rules based logging and can perform protocol analysis, content searching/matching and can be used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, CGI attacks, SMB probes, OS fingerprinting attempts, and much more. Snort has a real-time alerting capabilty, with alerts being sent to syslog, a separate "alert" file, or as a WinPopup message via Samba's smbclient Edit /etc/snort.conf to configure snort and use snort.d to start snort This rpm is different from previous rpms and while it will not clobber your current snortd file, you will need to modify it. There are 9 different packages available All of them require the base snort rpm. Additionally, you will need to chose a binary to install. /usr/sbin/snort should end up being a symlink to a binary in one of the following configurations: plain plain+flexresp mysql mysql+flexresp postgresql postgresql+flexresp snmp snmp+flexresp bloat mysql+postgresql+flexresp+snmp Please see the documentation in /usr/share/doc/snort-2.8.5.1 There are no rules in this package the license they are released under forbids us from repackaging them and redistributing them. -------------------------------------------------------------------------------- Update Information: Update to 2.8.5.1 which includes a fix for CVE-2009-3641 DoS (crash)while printing specially-crafted IPv6 packet using the -v option -------------------------------------------------------------------------------- ChangeLog: * Sun Oct 25 2009 Dennis Gilmore - 2.8.5.1-1 - update for CVE-2009-3641 * Sun Jul 26 2009 Fedora Release Engineering - 2.8.3.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Sun Apr 19 2009 Robert Scheck - 2.8.3.2-3 - Build require package libnet10-devel rather libnet10 * Wed Feb 25 2009 Fedora Release Engineering - 2.8.3.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Mon Feb 16 2009 Dennis Gilmore - 2.8.3.2-1 - update to 2.8.3.2 * Fri Jan 23 2009 Dennis Gilmore - 2.8.1-6 - rebuild for new mysql -------------------------------------------------------------------------------- References: [ 1 ] Bug #530863 - CVE-2009-3641 Snort: DoS (crash) while printing specially-crafted IPv6 packet using the -v option https://bugzilla.redhat.com/show_bug.cgi?id=530863 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update snort' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Snort contains a vulnerability in the rule matching algorithm that could result in a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200702-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Snort: Denial of Service Date: February 13, 2007 Bugs: #161632 ID: 200702-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Snort contains a vulnerability in the rule matching algorithm that could result in a Denial of Service. Background ========= Snort is a widely deployed intrusion detection program. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/snort < 2.6.1.2 > = 2.6.1.2 Description ========== Randy Smith, Christian Estan and Somesh Jha discovered that the rule matching algorithm of Snort can be exploited in a way known as a "backtracking attack" to perform numerous time-consuming operations. Impact ===== A remote attacker could send specially crafted network packets, which would result in the cessation of the detections and the consumption of the CPU resources. Workaround ========= There is no known workaround at this time. Resolution ========= All Snort users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-analyzer/snort-2.6.1.2" References ========= [ 1 ] CVE-2006-6931 https://www.cve.org/CVERecord?id=CVE-2006-6931 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200702-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Two vulnerabilities have been discoverd in Snort.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 297-1
The Snort stream4 preprocessor (spp_stream4) incorrectlycalculates segment size parameters during stream reassembly for certainsequence number ranges which can lead to an integer overflow that can beexpanded to a heap overflow.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200304-06 - - --------------------------------------------------------------------- PACKAGE : snort SUMMARY : Multiple Vulnerabilities in Snort Preprocessors DATE : 2003-04-28 07:07 UTC EXPLOIT : remote VERSIONS AFFECTED : =snort-2.0.0 CVE : CAN-2003-0209 CAN-2003-0033 - - --------------------------------------------------------------------- New (and correct) ID and updated CVE link. - From advisories: "The Sourcefire Vulnerability Research Team has learned of an integer overflow in the Snort stream4 preprocessor used by the Sourcefire Network Sensor product line. The Snort stream4 preprocessor (spp_stream4) incorrectly calculates segment size parameters during stream reassembly for certain sequence number ranges which can lead to an integer overflow that can be expanded to a heap overflow. The Snort stream4 flaw may lead to a denial of service (DoS) attack or remote command execution on a host running Snort. This attack can be launched by crafting TCP stream packets and transmitting them over a network segment that is being monitored by a vulnerable Snort implementation. In its default configuration, certain versions of snort are vulnerable to this attack, as is the default configuration of the Snort IDS." "Remote attackers may exploit the buffer overflow condition to run arbitrary code on a Snort sensor with the privileges of the Snort IDS process, which typically runs as the superuser. The vulnerable preprocessor is enabled by default. It is not necessary to establish an actual connection to a RPC portmapper service to exploit this vulnerability." Read the full advisories at: ;idxseccion=10 SOLUTION Itis recommended that all Gentoo Linux users who are running net-analyzer/snort upgrade to snort-2.0.0 as follows: emerge sync emerge snort emerge clean . Gentoo Linux alerts users to significant security flaws in Snort's Stream4 preprocessor, applicable to all releases before 2.9.18, recommending urgent updates to avert potential threats.. Snort Vulnerabilities, Gentoo Security Update, Stream4 Preprocessor Exploit. . Severity: Critical. LinuxSecurity.com Team
Remote attackers may exploit the buffer overflow condition to run arbitrary code on a Snort sensor with the privileges of the Snort IDS process, which typically runs as the superuser.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200303-6.1 - - --------------------------------------------------------------------- PACKAGE : snort SUMMARY : buffer overflow DATE : 2003-03-06 10:59 UTC EXPLOIT : remote VERSIONS AFFECTED : 1.9.1 CVE : CAN-2003-0033 - - --------------------------------------------------------------------- - From advisory: "Remote attackers may exploit the buffer overflow condition to run arbitrary code on a Snort sensor with the privileges of the Snort IDS process, which typically runs as the superuser. The vulnerable preprocessor is enabled by default. It is not necessary to establish an actual connection to a RPC portmapper service to exploit this vulnerability." Read the full advisory at: SOLUTION It is recommended that all Gentoo Linux users who are running net-analyzer/snort upgrade to snort-1.9.1 as follows: emerge sync emerge -u snort emerge clean - - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.