Vulnerabilities > CVE-2004-2652 - Remote Denial Of Service vulnerability in Snort DecodeTCPOptions

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
sourcefire
exploit available

Summary

The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference.

Vulnerable Configurations

Part Description Count
Application
Sourcefire
4

Exploit-Db

descriptionSnort 2.1/2.2 DecodeTCPOptions Remote Denial Of Service Vulnerability (1). CVE-2004-2652. Dos exploit for linux platform
idEDB-ID:25046
last seen2016-02-03
modified2004-12-22
published2004-12-22
reporterMarcin Zgorecki
sourcehttps://www.exploit-db.com/download/25046/
titleSnort 2.1/2.2 DecodeTCPOptions Remote Denial of Service Vulnerability 1