SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#175500

Snort Back Orifice preprocessor buffer overflow

Overview

A buffer overflow exists in the Snort Back Orifice preprocessor that may allow a remote, unauthenticated attacker to execute arbitrary code, possibly with elevated privileges.

I. Description

Snort is an open-source intrusion detection system (IDS). A lack of validation on attacker-controlled data may allow a buffer overflow to occur in the in Snort Back Orifice preprocessor. A remote, unauthenticated attacker may be able to trigger the buffer overflow by sending a specially crafted Back Orifice ping to a vulnerable Snort installation.

To exploit this vulnerability, an attacker does not need to send packets directly to the Snort sensor. It is sufficient to send packets to any of the hosts on the network monitored by Snort.

II. Impact

A remote attacker can execute arbitrary code with the privileges of the Snort process, typically root or SYSTEM.

III. Solution

Update

This issue has been addressed in Snort version 2.4.3.

Disable Snort Back Orifice preprocessor

Disabling the Snort Back Orifice preprocessor will mitigate this vulnerability. However, without the Snort preprocessor, the Snort sensor will not detect or prevent Back Orifice traffic. Snort suggests the following steps to disable the Back Orifice preprocessor:

    The Back Orifice preprocessor can be disabled by commenting out the line "preprocessor bo" in snort.conf. This can be done in any text editor using the following procedure:

    1. Locate the line "preprocessor bo"
    2. Comment out this line by preceding it with a hash (#). The new line will look like "#preprocessor bo"
    3. Save the file
    4. Restart snort

Systems Affected

VendorStatusDate Updated
3com, Inc.Unknown18-Oct-2005
AlcatelUnknown18-Oct-2005
Apple Computer, Inc.Not Vulnerable9-Nov-2005
AT&TUnknown18-Oct-2005
Avaya, Inc.Not Vulnerable18-Oct-2005
Avici Systems, Inc.Unknown18-Oct-2005
Borderware TechnologiesUnknown18-Oct-2005
BroUnknown11-Nov-2005
Charlotte's Web NetworksUnknown18-Oct-2005
Check Point Software TechnologiesUnknown18-Oct-2005
Chiaro Networks, Inc.Unknown18-Oct-2005
CIACUnknown11-Nov-2005
Cisco Systems, Inc.Unknown18-Oct-2005
Computer AssociatesUnknown18-Oct-2005
Computer Associates eTrust Security ManagementUnknown10-Nov-2005
Conectiva Inc.Unknown18-Oct-2005
Cray Inc.Unknown18-Oct-2005
D-Link Systems, Inc.Unknown18-Oct-2005
Data Connection, Ltd.Unknown18-Oct-2005
Debian LinuxNot Vulnerable11-Nov-2005
EMC, Inc. (formerly Data General Corporation)Unknown18-Oct-2005
Engarde Secure LinuxUnknown18-Oct-2005
Enterasys NetworksUnknown10-Nov-2005
EricssonUnknown18-Oct-2005
eSoft, Inc.Unknown18-Oct-2005
Extreme NetworksUnknown18-Oct-2005
F5 Networks, Inc.Not Vulnerable19-Oct-2005
Fedora ProjectUnknown18-Oct-2005
Force10 Networks, Inc.Unknown18-Oct-2005
Fortinet, Inc.Unknown18-Oct-2005
Foundry Networks, Inc.Unknown18-Oct-2005
FreeBSD, Inc.Vulnerable18-Oct-2005
FujitsuUnknown18-Oct-2005
Gentoo LinuxUnknown18-Oct-2005
Global Technology AssociatesNot Vulnerable18-Oct-2005
GNU netfilterUnknown18-Oct-2005
Hewlett-Packard CompanyUnknown18-Oct-2005
HitachiNot Vulnerable20-Oct-2005
HyperchipUnknown18-Oct-2005
IBM CorporationUnknown18-Oct-2005
Immunix Communications, Inc.Unknown18-Oct-2005
Ingrian Networks, Inc.Unknown18-Oct-2005
Intel CorporationUnknown18-Oct-2005
Internet Security Systems, Inc.Not Vulnerable18-Oct-2005
IntotoNot Vulnerable11-Nov-2005
IP FilterUnknown18-Oct-2005
Juniper Networks, Inc.Not Vulnerable20-Oct-2005
Linksys (A division of Cisco Systems)Unknown18-Oct-2005
Lucent TechnologiesUnknown18-Oct-2005
Luminous NetworksUnknown18-Oct-2005
Mandriva, Inc.Unknown18-Oct-2005
McAfeeUnknown10-Nov-2005
Microsoft CorporationUnknown18-Oct-2005
MontaVista Software, Inc.Unknown18-Oct-2005
Multinet (owned Process Software Corporation)Unknown18-Oct-2005
Multitech, Inc.Unknown18-Oct-2005
NEC CorporationUnknown18-Oct-2005
NetBSDUnknown18-Oct-2005
Network Appliance, Inc.Unknown18-Oct-2005
NextHop Technologies, Inc.Not Vulnerable18-Oct-2005
Nortel Networks, Inc.Vulnerable19-Oct-2005
Novell, Inc.Unknown18-Oct-2005
OpenBSDUnknown18-Oct-2005
Openwall GNU/*/LinuxNot Vulnerable18-Oct-2005
QNX, Software Systems, Inc.Unknown18-Oct-2005
Red Hat, Inc.Not Vulnerable18-Oct-2005
Redback Networks, Inc.Unknown18-Oct-2005
Riverstone Networks, Inc.Unknown18-Oct-2005
Secure Computing Network Security DivisionNot Vulnerable18-Oct-2005
Sequent Computer Systems, Inc.Unknown18-Oct-2005
Silicon Graphics, Inc.Unknown18-Oct-2005
Slackware Linux Inc.Unknown18-Oct-2005
SnortVulnerable18-Oct-2005
Sony CorporationUnknown18-Oct-2005
SourcefireVulnerable26-Oct-2005
StonesoftNot Vulnerable20-Oct-2005
Sun Microsystems, Inc.Not Vulnerable18-Oct-2005
SUSE LinuxVulnerable19-Oct-2005
Symantec, Inc.Unknown18-Oct-2005
The SCO GroupUnknown18-Oct-2005
TippingPoint, Technologies, Inc.Unknown10-Nov-2005
Trustix Secure LinuxUnknown18-Oct-2005
TurbolinuxUnknown18-Oct-2005
UbuntuVulnerable19-Oct-2005
UnisysUnknown18-Oct-2005
Watchguard Technologies, Inc.Not Vulnerable18-Oct-2005
Wind River Systems, Inc.Unknown18-Oct-2005
ZyXELUnknown18-Oct-2005

References

http://www.us-cert.gov/cas/techalerts/TA05-291A.html
http://www.snort.org/pub-bin/snortnews.cgi#99
http://www.snort.org/docs/change_logs/2.4.3/Changelog.txt
http://www.snort.org/docs/snort_htmanuals/htmanual_2.4/node11.html#SECTION00310000000000000000
http://xforce.iss.net/xforce/alerts/id/207
http://secunia.com/advisories/17220/

Credit

This vulnerability was researched and reported by Internet Security Systems (ISS).

This document was written by Art Manion and Jeff Gennari.

Other Information

Date Public10/18/2005
Date First Published10/18/2005 06:13:56 PM
Date Last Updated11/11/2005
CERT Advisory 
CVE NameCAN-2005-3252
US-CERT Technical Alerts 
Metric31.05
Document Revision37

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader