Bug 3154 - snort vulns upgrade to 2.0
: snort vulns upgrade to 2.0
Status: CLOSED FIXED
Product: Security
Classification: Unclassified
Component: General / Other Security Issue
: unspecified
: Other other
: P2 normal
Assigned To: SM Security List
http://www.snort.org/advisories/snort...
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2003-04-17 13:42 UTC by Seth Woolley
Modified: 2003-10-19 23:17 UTC (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Seth Woolley 2003-04-17 13:42:31 UTC
http://www.snort.org/advisories/snort-2003-04-16-1.txt

/me is upgrading it.
Comment 1 Seth Woolley 2003-04-17 13:43:56 UTC
Disable affected preprocessor modules

   Sites  that  are  unable to immediately upgrade affected Snort sensors
   may  prevent  exploitation of this vulnerability by commenting out the
   affected preprocessor modules in the "snort.conf" configuration file.

   To prevent exploitation of VU#139129, comment out the following line:

     preprocessor stream4_reassemble

   To prevent exploitation of VU#916785, comment out the following line:

     preprocessor rpc_decode: 111 32771

   After commenting out the affected modules, send a SIGHUP signal to the
   affected   Snort  process  to  update  the  configuration.  Note  that
   disabling these modules may have adverse affects on a sensor's ability
   to correctly process RPC record fragments and TCP packet fragments. In
   particular,  disabling  the "stream4" preprocessor module will prevent
   the Snort sensor from detecting a variety of IDS evasion attacks.
Comment 2 Seth Woolley 2003-04-17 13:44:45 UTC
http://www.cert.org/advisories/CA-2003-13.html
Comment 3 Seth Woolley 2003-04-17 14:02:13 UTC
devel, test, stable updated.  Now posting to news.sourcemage.org.
Comment 4 Robert Helgesson 2003-04-17 15:20:55 UTC
Nice work Seth.
Comment 5 games 2003-10-19 23:17:20 UTC
if any of these still have issues outstanding then they can be reopened, but
most  have just been overlooked/forgotten
("these" refers to the 611 fixed but not closed bugs I just found in our database)