CVE-2004-2652

Snort - Denial of Service via Invalid TCP/IP Options in DecodeTCPOptions

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2004-2652. PoCs published by Antimatt3r, Marcin Zgorecki.

AI-analyzed exploit summary This exploit targets a denial-of-service vulnerability in Snort's DecodeTCPOptions() function by sending a malformed TCP packet with specific options. The crafted packet triggers a crash in Snort, disrupting its functionality.

Description

The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Antimatt3r · cdoslinux
https://www.exploit-db.com/exploits/25047

This exploit targets a denial-of-service vulnerability in Snort's DecodeTCPOptions() function by sending a malformed TCP packet with specific options. The crafted packet triggers a crash in Snort, disrupting its functionality.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Snort (versions affected by CVE-2004-2652)
No auth needed
Prerequisites: Network access to the target Snort instance · Ability to send raw TCP packets
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Marcin Zgorecki · cdoslinux
https://www.exploit-db.com/exploits/25046

This exploit targets a denial-of-service vulnerability in Snort's DecodeTCPOptions() function by sending a malformed TCP packet with an invalid MSS option. The PoC constructs a raw TCP packet with a crafted TCP option to trigger the crash.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Snort >= 2.1.3
No auth needed
Prerequisites: Raw socket permissions · Network access to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/13664
Exploit, Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1012656
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18689
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12084
Exploit vdb-entry x_refsource_osvdb
http://www.osvdb.org/12578
Various Sources x_refsource_confirm
http://www.snort.org/arc_news/

Scores

EPSS 0.1119
EPSS Percentile 95.4%

Details

Status published
Products (4)
sourcefire/snort 2.1.0
sourcefire/snort 2.1.1_rc1
sourcefire/snort 2.1.3
sourcefire/snort 2.2
Published Dec 31, 2004
Tracked Since Feb 18, 2026