APP: Snort DCE RPC Processor Denial of Service

This signature detects attempts to exploit a known vulnerability in the Sourcefire Snort Intrusion Detection System. A successful attack can lead to a buffer overflow and denial of service.

Extended Description

Snort IDS and Sourcefire Intrusion Sensor are prone to a stack-based buffer-overflow vulnerability because the network intrusion detection (NID) systems fail to handle specially crafted 'DCE' and 'RPC' network packets. An attacker can exploit this issue to execute malicious code in the context of the user running the affected application. Failed attempts will likely cause these applications to crash.

Affected Products

Nortel_networks threat_protection_system_defense_center,Debian linux

References

BugTraq: 22616

CVE: CVE-2006-5276

Short Name
APP:SNORT:DCE-RPC-DOS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
CVE-2006-5276 DCE Denial Processor RPC Service Snort bid:22616 of
Release Date
02/28/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3728
False Positive
Unknown
Vendors

Red_hat

Suse

Gentoo

Snort_project

Nortel_networks

Debian

CVSS Score

10.0

Found a potential security threat?