CVE-2006-5276: Buffer Overflow
Description of problem:
Sourcefire has learned of a remotely exploitable vulnerability in the Snort DCE/RPC preprocessor. This preprocessor is vulnerable to a stack-based buffer overflow that could potentially allow attackers to execute code with the same privileges as the Snort binary. Sourcefire has prepared updates for Snort open-source software to address this issue.
Version-Release number of selected component (if applicable): Snort Versions Affected:
Snort 2.6.1, 2.6.1.1, and 2.6.1.2 Snort 2.7.0 beta 1
How reproducible:
Steps to Reproduce: 1. 2. 3. Actual results:
Expected results:
Additional info:
Other sources
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5276?
CVE-2006-5276 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2006-5276?
To mitigate CVE-2006-5276, users should upgrade to Snort version 2.7 or later.
What systems are affected by CVE-2006-5276?
CVE-2006-5276 affects specific versions of Snort, Sourcefire Intrusion Sensor, and certain other packages.
Can CVE-2006-5276 be exploited remotely?
Yes, CVE-2006-5276 is a remotely exploitable stack-based buffer overflow vulnerability.
What can an attacker do if they exploit CVE-2006-5276?
An attacker exploiting CVE-2006-5276 could execute arbitrary code with the same privileges as the Snort binary.