CVE-2007-1398: High severity Linux Linux kernel vulnerability
Published Mar 10, 2007
·Updated
The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ipconntrack module loaded, allows remote attackers to cause a denial of service (segmentation fault and application crash) via certain UDP packets produced by sendmorefragpacket and sendoverlappacket.
Affected Software
4 affected components
Linux Linux kernel
Snort Snort=2.6.1.1
Snort Snort=2.6.1.2
Snort Snort=2.7_beta1
Event History
Mar 10, 2007
CVE Published
10:19 PM
Data Sourced
10:19 PM
DescriptionWeaknessAffected Software
Mar 11, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1398?
CVE-2007-1398 is classified as a denial-of-service vulnerability.
2
How do I fix CVE-2007-1398?
To fix CVE-2007-1398, ensure the ip_conntrack module is loaded before using the frag3 preprocessor in Snort.
3
Which versions of Snort are affected by CVE-2007-1398?
CVE-2007-1398 affects Snort versions 2.6.1.1, 2.6.1.2, and 2.7.0 beta.
4
Can CVE-2007-1398 be exploited remotely?
Yes, CVE-2007-1398 can be exploited remotely via specially crafted UDP packets.
5
What happens when CVE-2007-1398 is exploited?
Exploiting CVE-2007-1398 can cause a segmentation fault and crash the Snort application.