Snort ICMP远程拒绝服务攻击漏洞

Snort ICMP远程拒绝服务攻击漏洞

漏洞ID 1106571 漏洞类型 边界条件错误
发布时间 2002-01-10 更新时间 2005-05-02
图片[1]-Snort ICMP远程拒绝服务攻击漏洞-安全小百科CVE编号 CVE-2002-0115
图片[2]-Snort ICMP远程拒绝服务攻击漏洞-安全小百科CNNVD-ID CNNVD-200203-067
漏洞平台 Multiple CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/21213
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200203-067
|漏洞详情
Snort是一个轻量级的入侵检测系统(intrusiondetectionsystem)。它最初是在Linux平台下开发的,现在已经被移植到Windows平台下。Snort能够灵活地对网络流量提供强大的分析能力,能够检测到大多数的网络攻击。某些版本的Snort设计上存在漏洞,可以使远程攻击者对Snort程序进行拒绝服务攻击。当Snort收到一个特别构造的ICMP数据包时,Snort守护进程就会崩溃。这是由于Snort错误地定义了ICMP最小头为8字节。要让Snort恢复功能需要重启进程。很可能以前的Snort版本也受此漏洞的影响。
|漏洞EXP
source: http://www.securityfocus.com/bid/3849/info

Snort is a network intrusion detection system (IDS). It is originally written for Linux and Unix systems, although it has also been ported to run under Microsoft Windows. Snort is capable of flexible and powerful content analysis of network traffic, and can detect a large number of attack attempts.

An error exists in some versions of Snort. If a maliciously constructed ICMP packet is received, the daemon will crash. This is caused because Snort erroneously defines the minimum ICMP header size as 8 bytes. A restart will be required to regain normally functionality. 

ping -c1 -s1 host
|参考资料

来源:XF
名称:snort-icmp-dos(7874)
链接:http://www.iss.net/security_center/static/7874.php
来源:BUGTRAQ
名称:20020110Re:Snortcoredumped
链接:http://online.securityfocus.com/cgi-bin/archive.pl?id=1&start;=2002-03-08&end;=2002-03-14∣=249623&threads;=1
来源:BUGTRAQ
名称:20020110Snortcoredumped
链接:http://online.securityfocus.com/archive/1/249340
来源:BID
名称:3849
链接:http://www.securityfocus.com/bid/3849
来源:OSVDB
名称:2022
链接:http://www.osvdb.org/2022

相关推荐: vpopmail-CGIApps Remote Command Execution Vulnerability

vpopmail-CGIApps Remote Command Execution Vulnerability 漏洞ID 1101430 漏洞类型 Input Validation Error 发布时间 2002-10-24 更新时间 2002-10-24 C…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享