Title : Snort "http_inspect" Preprocessor URL Handling Detection Bypass Vulnerability VUPEN ID : VUPEN/ADV-2006-2119 CVE ID : CVE-2006-2769
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-06-02
Technical Description
A vulnerability has been identified in Snort, which could be exploited by attackers to bypass security policies. This flaw is due to an error in the "http_inspect" preprocessor that fails to properly validate URLs containing a carriage return character at the end, which could be exploited by attackers to bypass "uricontent" detection rules via specially crafted HTTP requests.