CVE Vulnerabilities

CVE-2006-2769

Published: Jun 02, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass uricontent rules via a carriage return (r) after the URL and before the HTTP declaration.

Affected Software

NameVendorStart VersionEnd Version
SnortSourcefire2.4 (including)2.4 (including)
SnortSourcefire2.4.1 (including)2.4.1 (including)
SnortSourcefire2.4.2 (including)2.4.2 (including)
SnortSourcefire2.4.3 (including)2.4.3 (including)
SnortSourcefire2.4.4 (including)2.4.4 (including)
SnortUbuntudapper*
SnortUbuntudevel*
SnortUbuntuedgy*
SnortUbuntufeisty*
SnortUbuntugutsy*
SnortUbuntuhardy*
SnortUbuntuintrepid*
SnortUbuntujaunty*
SnortUbuntukarmic*

References