CVE-2009-3641: Medium severity pfsense snort package vulnerability
Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packet that uses the (1) TCP or (2) ICMP protocol.
Other sources
Snort upstream has released 2.8.5.1 version, addressing one security issue (from upstream release notes):
Fixed potential segfault when printing IPv6 packets using the -v option. Thanks to Laurent Gaffie for reporting this issue.
References: ----------- http://vrt-sourcefire.blogspot.com/2009/10/snort-2851-release.html http://www.snort.org/downloads http://secunia.com/advisories/37135/
PoC: http://seclists.org/fulldisclosure/2009/Oct/299 ----
Credit: ------- Laurent Gaffié
CVE Request: ------------ http://www.openwall.com/lists/oss-security/2009/10/25/3
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3641?
CVE-2009-3641 has a denial of service impact on affected Snort versions.
How do I fix CVE-2009-3641?
To fix CVE-2009-3641, upgrade to Snort version 2.8.5.1 or later.
What are the affected versions of Snort for CVE-2009-3641?
CVE-2009-3641 affects Snort versions prior to 2.8.5.1, including various earlier versions.
What type of attack does CVE-2009-3641 enable?
CVE-2009-3641 allows remote attackers to exploit a crafted IPv6 packet to cause an application crash.
Is CVE-2009-3641 specific to any protocols?
Yes, CVE-2009-3641 specifically affects TCP and ICMP protocols.