CVE Vulnerabilities

CVE-2006-2769

Published: Jun 02, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass uricontent rules via a carriage return (r) after the URL and before the HTTP declaration.

Affected Software

Name Vendor Start Version End Version
Snort Sourcefire 2.4 (including) 2.4 (including)
Snort Sourcefire 2.4.1 (including) 2.4.1 (including)
Snort Sourcefire 2.4.2 (including) 2.4.2 (including)
Snort Sourcefire 2.4.3 (including) 2.4.3 (including)
Snort Sourcefire 2.4.4 (including) 2.4.4 (including)
Snort Ubuntu dapper *
Snort Ubuntu devel *
Snort Ubuntu edgy *
Snort Ubuntu feisty *
Snort Ubuntu gutsy *
Snort Ubuntu hardy *
Snort Ubuntu intrepid *
Snort Ubuntu jaunty *
Snort Ubuntu karmic *

References