20030415 CORE-2003-0307: Snort TCP Stream Reassembly Integer Overflow Vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=105043563016235&w=2 CVE-2003-0209
Snort 1.9.1 - 'p7snort191.sh' Remote Command Execution
Record summary
CVE-2003-0209 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSnort 1.9.1 - 'p7snort191.sh' Remote Command ExecutionExploitDB exploitby truffNot analyzed1 file
References
1220030422 GLSA: snort (200304-05)mailing list
http://marc.info/?l=bugtraq&m=105103586927007&w=2 20030423 Snort <=1.9.1 exploitmailing list
http://marc.info/?l=bugtraq&m=105111217731583&w=2 20030428 GLSA: snort (200304-06)mailing list
http://marc.info/?l=bugtraq&m=105154530427824&w=2 ESA-20030430-013Vendor advisory
http://marc.info/?l=bugtraq&m=105172790914107&w=2 CA-2003-13Third-party advisory
http://www.cert.org/advisories/CA-2003-13.html coresecurity.com
http://www.coresecurity.com/common/showdoc.php?idx=313&idxseccion=10 DSA-297Vendor advisory
http://www.debian.org/security/2003/dsa-297 VU#139129Third-party advisory
http://www.kb.cert.org/vuls/id/139129 MDKSA-2003:052Vendor advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2003:052 7178vdb entry
http://www.securityfocus.com/bid/7178 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0209