[News]Bot
02-20-2007, 09:30 PM
Remote Code Execution Hole Found In Snort (http://rss.slashdot.org/~r/Slashdot/slashdot/~3/93634015/article.pl):
Palljon1123 writes "A stack-based buffer overflow in the Snort intrusion detection system could leave government and enterprise installations vulnerable to remote unauthenticated code execution attacks. The flaw, found by researchers at IBM's ISS X-Force, affects the Snort DCE/RPC preprocessor and could be used to execute code with the same privileges (usually root or SYSTEM) as the Snort binary. No user action is required." Sourcefire has an update to fix the vulnerability in versions 2.6.1, 2.6.1.1, and 2.6.1.2; Heise Security spells out the workaround for the 2.7.0 beta version. http://rss.slashdot.org/~a/Slashdot/slashdot?i=N1oNrB</img> (http://rss.slashdot.org/~a/Slashdot/slashdot?a=N1oNrB)
http://rss.slashdot.org/~r/Slashdot/slashdot/~4/93634015
Palljon1123 writes "A stack-based buffer overflow in the Snort intrusion detection system could leave government and enterprise installations vulnerable to remote unauthenticated code execution attacks. The flaw, found by researchers at IBM's ISS X-Force, affects the Snort DCE/RPC preprocessor and could be used to execute code with the same privileges (usually root or SYSTEM) as the Snort binary. No user action is required." Sourcefire has an update to fix the vulnerability in versions 2.6.1, 2.6.1.1, and 2.6.1.2; Heise Security spells out the workaround for the 2.7.0 beta version. http://rss.slashdot.org/~a/Slashdot/slashdot?i=N1oNrB</img> (http://rss.slashdot.org/~a/Slashdot/slashdot?a=N1oNrB)
http://rss.slashdot.org/~r/Slashdot/slashdot/~4/93634015