>> Sourcefire Intrusion Sensor and Snort DCE/RPC Preprocessor Overflow Vulnerability
Title : Sourcefire Intrusion Sensor and Snort DCE/RPC Preprocessor Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-0656 CVE ID : CVE-2006-5276
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-02-20
Technical Description
A vulnerability has been identified in Sourcefire Intrusion Sensor and Snort, which could be exploited by attackers to cause a denial of service or execute arbitrary commands. This issue is due to a buffer overflow error within the DCE/RPC preprocessor (enabled by default) when processing malformed data via the "ReassembleSMBWriteX()" and "ReassembleDCERPCRequest()" functions, which could be exploited by attackers to compromise a vulnerable system by sending specially crafted packets to a network being monitored by a vulnerable application.