CVE-2004-2652
Last modified
CVE-2004-2652 is a vulnerability of currently unknown severity. The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.. EPSS estimates a 11.19% chance of exploitation in the next 30 days.
Description
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sourcefire | Snort | 2.1.0 |
| Sourcefire | Snort | 2.1.1_rc1 |
| Sourcefire | Snort | 2.1.3 |
| Sourcefire | Snort | 2.2 |
References
- http://secunia.com/advisories/13664Patch, Vendor Advisory
- http://securitytracker.com/id?1012656Exploit, Patch
- http://taosecurity.blogspot.com/2004/12/details-on-snort-dos-condition-you-may.htmlExploit, Vendor Advisory
- http://www.osvdb.org/12578Exploit
- http://secunia.com/advisories/13664Patch, Vendor Advisory
- http://securitytracker.com/id?1012656Exploit, Patch
- http://taosecurity.blogspot.com/2004/12/details-on-snort-dos-condition-you-may.htmlExploit, Vendor Advisory
- http://www.osvdb.org/12578Exploit
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2652?
How severe is CVE-2004-2652?
How do I fix CVE-2004-2652?
Are you affected by CVE-2004-2652?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
