CVE-2006-2769: Medium severity sourcefire snort vulnerability
Published Jun 2, 2006
·Updated
The HTTP Inspect preprocessor (httpinspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration.
Affected Software
5 affected components
Sourcefire Snort=2.4
Sourcefire Snort=2.4.1
Sourcefire Snort=2.4.2
Sourcefire Snort=2.4.3
Sourcefire Snort=2.4.4
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jun 2, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2769?
CVE-2006-2769 is considered a medium severity vulnerability that allows attackers to bypass security rules.
2
How do I fix CVE-2006-2769?
To fix CVE-2006-2769, upgrade Snort to a version later than 2.4.4.
3
What versions of Snort are affected by CVE-2006-2769?
CVE-2006-2769 affects Snort versions 2.4.0 through 2.4.4.
4
What type of attack does CVE-2006-2769 facilitate?
CVE-2006-2769 facilitates a method for remote attackers to bypass 'uricontent' rules in Snort.
5
How can I verify if my Snort installation is vulnerable to CVE-2006-2769?
You can verify your Snort installation by checking if it is running any version from 2.4.0 to 2.4.4.