CVE-2008-1804

EPSS 0.26%

snort - rules bypass

Published: 5/22/2008Modified: 6/30/2024
Also known as:DEBIAN-CVE-2008-1804DTSA-173-1

Description

preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, which allows remote attackers to bypass detection rules by using a different TTL for each fragment.

Affected packages (2)

References (15)