MEDIUM
Snort: DoS (crash) while printing specially-crafted IPv6 packet using the -v option
Published Oct 28, 2009
4.3
MEDIUMCVSS 2.0
EPSS 38.78%
Description
Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packet that uses the (1) TCP or (2) ICMP protocol.
Affected products
No data.
OR
- ≤ 2.8.3.5
- 1.6
- 1.8.0
- 1.8.1
- 1.8.2
- 1.8.3
- 1.8.4
- 1.8.5
- 1.8.6
- 1.8.7
- 1.9.0
- 1.9.1
- 2.0
- 2.0
- 2.6.1
- 2.6.1.1
- 2.6.1.2
- 2.6.2
- 2.7_beta1
- 2.8.0
- 2.8.2.2
- 2.8.3
- 2.8.3.1
- 2.8.3.2
- 2.8.3.4
- 2.8.3.4.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (16)
- http://dl.snort.org/snort-current/release_notes_2851.txt x_refsource_CONFIRMVendor Advisory
- http://marc.info/?l=oss-security&m=125649553414700&w=2 mailing-listx_refsource_MLIST
- http://seclists.org/fulldisclosure/2009/Oct/299 mailing-listx_refsource_FULLDISCExploitPatch
- http://secunia.com/advisories/37135 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1023076 vdb-entryx_refsource_SECTRACK
- http://vrt-sourcefire.blogspot.com/2009/10/snort-2851-release.html x_refsource_CONFIRMPatch
- http://www.openwall.com/lists/oss-security/2009/10/25/5 mailing-listx_refsource_MLIST
- http://www.osvdb.org/59159 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/36795 vdb-entryx_refsource_BIDExploitPatch
- http://www.vupen.com/english/advisories/2009/3014 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-3641 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=530863 x_refsource_CONFIRMExploitIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-3616 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53912 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-3641
- https://www.cve.org/CVERecord?id=CVE-2009-3641
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 28, 2009
Updated Aug 7, 2024
Reserved Oct 9, 2009
Link CVE-2009-3641
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-3616 Assigner redhat
Published Oct 28, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-3616