Jennifer,
I might be missing something, but when I click the
http://www.snort.org/dl/link all I see is the
2.4.2 version, not the 2.4.3.
Thanks,
Sam
On 10/18/05, Jennifer Steffens <jennifer...@sourcefire.com> wrote:
>
> Subject: Fix and Mitigation Available for Snort Vulnerability
>
> The Sourcefire Vulnerability Research Team (VRT) has learned of a
> vulnerability in Snort v2.4.0 and higher. Users are only vulnerable if
> the Back Orifice preprocessor is enabled. Snort v2.4.3 has been released
> to correct the issue and detailed instructions for mitigating the issue
> by disabling the Back Orifice preprocessor are below.
>
>
> Snort v2.4.3
>
> In addition to fixing the vulnerability, this version includes a
> mechanism to detect exploits against vulnerable sensors and, optionally
> for inline sensors, drop the offending traffic. These features enable a
> phased approach to upgrading while protecting unpatched sensors.
> Detection capabilities are part of the new preprocessor and therefore
> are available to all users regardless of subscription status.
>
> In addition to the source tarball, postgres, mysql and plain RPMs and a
> win32 installer are available at http://www.snort.org/dl. Please
> remember that updated rules are only included in major releases. For
> updated rules, visit http://www.snort.org/rules/.
>
>
> Mitigation Instructions:
>
> The Back Orifice preprocessor can be disabled by commenting out the line
> "preprocessor bo" in snort.conf. This can be done in any text editor
> using the following procedure:
>
> 1. Locate the line "preprocessor bo"
> 2. Comment out this line by preceding it with a hash (#). The new line
> will look like "#preprocessor bo"
> 3. Save the file
> 4. Restart snort
>
>
> Background:
>
> On Thursday, October 13th Sourcefire was contacted by USCERT with news
> of a vulnerability in Snort. We used the subsequent days to verify the
> vulnerability and to prepare mitigation strategies and the software
> updates necessary to fix the vulnerability for both Sourcefire customers
> and Snort users. While it cannot be said that no other problems will
> ever be found in the Snort code base, we can state that we will redouble
> our efforts to ensure the security of the system so many people have
> come to rely on for the detection of network-based threats. Sourcefire
> will also continue to work with the most sophisticated testing
> facilities in the industry to assure that every reasonable step is being
> taken to provide the most secure code base possible.
>
>
> Technical Details:
> The Back Orifice preprocessor contains a stack-based buffer overflow.
> This vulnerability could be leveraged by an attacker to execute code
> remotely on a Snort sensor where the Back Orifice preprocessor is
> enabled. However, there are a number of factors that make remote code
> execution difficult to achieve across different builds of Snort on
> different platforms, even on the same platform with different compiler
> versions, and it is more likely that an attacker could use the
> vulnerability as a denial of service attack.
>
>
> If you have any questions, please let us know at snort...@sourcefire.co=
m
>
> Thanks,
> Jennifer
>
>
> --
> Jennifer S. Steffens
> Director, Snort Product Management | Sourcefire, Inc.
> W: 410.423.1930 | C: 202.409.7707
> www.sourcefire.com <http://www.sourcefire.com> | www.snort.org<http://www=
.snort.org>
>
>
> -------------------------------------------------------
> This SF.Net email is sponsored by:
> Power Architecture Resource Center: Free content, downloads, discussions,
> and more. http://solutions.newsforge.com/ibmarch.tmpl
> _______________________________________________
> Snort-users mailing list
> Snort...@lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users
>
------=_Part_28219_2690732.1129672490452
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline
<div>Jennifer,</div>
<div> </div>
<div>I might be missing something, but when I click the <a href=3D"http://w=
ww.snort.org/dl/">http://www.snort.org/dl/</a> link all I see is the 2=
.4.2 version, not the 2.4.3.</div>
<div> </div>
<div>Thanks,</div>
<div>Sam</div>
<div><br><br> </div>
<div><span class=3D"gmail_quote">On 10/18/05, <b class=3D"gmail_sendername"=
>Jennifer Steffens</b> <<a href=3D"mailto:jennifer.steffens@sourcefire.c=
om">jennifer...@sourcefire.com</a>> wrote:</span>
<blockquote class=3D"gmail_quote" style=3D"PADDING-LEFT: 1ex; MARGIN: 0px 0=
px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">Subject: Fix and Mitigation Avai=
lable for Snort Vulnerability<br><br>The Sourcefire Vulnerability Research =
Team (VRT) has learned of a
<br>vulnerability in Snort v2.4.0 and higher. Users are only vulnerable if<=
br>the Back Orifice preprocessor is enabled. Snort v2.4.3 has been released=
<br>to correct the issue and detailed instructions for mitigating the issue
<br>by disabling the Back Orifice preprocessor are below.<br><br><br>Snort =
v2.4.3<br><br>In addition to fixing the vulnerability, this version include=
s a<br>mechanism to detect exploits against vulnerable sensors and, optiona=
lly
<br>for inline sensors, drop the offending traffic. These features enable a=
<br>phased approach to upgrading while protecting unpatched sensors.<br>Det=
ection capabilities are part of the new preprocessor and therefore<br>are a=
vailable to all users regardless of subscription status.
<br><br>In addition to the source tarball, postgres, mysql and plain RPMs a=
nd a<br>win32 installer are available at <a href=3D"http://www.snort.org/dl=
">http://www.snort.org/dl</a>. Please<br>remember that updated rules are on=
ly included in major releases. For
<br>updated rules, visit <a href=3D"http://www.snort.org/rules/">http://www=
.snort.org/rules/</a>.<br><br><br>Mitigation Instructions:<br><br>The Back =
Orifice preprocessor can be disabled by commenting out the line<br>"pr=
eprocessor bo" in=20
snort.conf. This can be done in any text editor<br>using the following proc=
edure:<br><br>1. Locate the line "preprocessor bo"<br>2. Comment =
out this line by preceding it with a hash (#). The new line<br>will look li=
ke "#preprocessor bo"
<br>3. Save the file<br>4. Restart snort<br><br><br>Background:<br><br>On T=
hursday, October 13th Sourcefire was contacted by USCERT with news<br>of a =
vulnerability in Snort. We used the subsequent days to verify the<br>vulner=
ability and to prepare mitigation strategies and the software
<br>updates necessary to fix the vulnerability for both Sourcefire customer=
s<br>and Snort users. While it cannot be said that no other problems will<b=
r>ever be found in the Snort code base, we can state that we will redouble
<br>our efforts to ensure the security of the system so many people have<br=
>come to rely on for the detection of network-based threats. Sourcefire<br>=
will also continue to work with the most sophisticated testing<br>facilitie=
s in the industry to assure that every reasonable step is being
<br>taken to provide the most secure code base possible.<br><br><br>Technic=
al Details:<br>The Back Orifice preprocessor contains a stack-based buffer =
overflow.<br>This vulnerability could be leveraged by an attacker to execut=
e code
<br>remotely on a Snort sensor where the Back Orifice preprocessor is<br>en=
abled. However, there are a number of factors that make remote c=
ode<br>execution difficult to achieve across different builds of Snort on<b=
r>different platforms, even on the same platform with different compiler
<br>versions, and it is more likely that an attacker could use the<br>vulne=
rability as a denial of service attack.<br><br><br>If you have any question=
s, please let us know at <a href=3D"mailto:snort...@sourcefire.com">snort=
-te...@sourcefire.com
</a><br><br>Thanks,<br>Jennifer<br><br><br>--<br>Jennifer S. Steffens<br>Di=
rector, Snort Product Management | Sourcefire, Inc.<br>W: 410.423.1930 | C:=
202.409.7707<br><a href=3D"http://www.sourcefire.com">www.sourcefire.com
</a> | <a href=3D"http://www.snort.org">www.snort.org</a><br><br><br>------=
-------------------------------------------------<br>This SF.Net email is s=
ponsored by:<br>Power Architecture Resource Center: Free content, downloads=
, discussions,
<br>and more. <a href=3D"http://solutions.newsforge.com/ibmarch.tmpl">http:=
//solutions.newsforge.com/ibmarch.tmpl</a><br>_____________________________=
__________________<br>Snort-users mailing list<br><a href=3D"mailto:Snort-u=
se...@lists.sourceforge.net">
Snort...@lists.sourceforge.net</a><br>Go to this URL to change user opti=
ons or unsubscribe:<br><a href=3D"https://lists.sourceforge.net/lists/listi=
nfo/snort-users">https://lists.sourceforge.net/lists/listinfo/snort-users
</a><br>Snort-users list archive:<br><a href=3D"http://www.geocrawler.com/r=
edir-sf.php3?list=3Dsnort-users">http://www.geocrawler.com/redir-sf.php3?li=
st=3Dsnort-users</a><br></blockquote></div><br>
------=_Part_28219_2690732.1129672490452--
-------------------------------------------------------
This SF.Net email is sponsored by:
Power Architecture Resource Center: Free content, downloads, discussions,
and more. http://solutions.newsforge.com/ibmarch.tmpl
_______________________________________________
Snort-users mailing list
Snort...@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
-----Original Message-----
From: snort-us...@lists.sourceforge.net
[mailto:snort-us...@lists.sourceforge.net] On Behalf Of Jennifer
Steffens
Sent: Tuesday, October 18, 2005 5:31 PM
To: Sam Evans
Cc: snort-users @ lists. sourceforge. net
Subject: Re: [Snort-users] Fixes and Mitigation Instructions Available
for Snort Back Orifice Vulnerability
Sam,
Can you try refreshing the page? The 2.4.3 version is there for me. The=20
actual link is http://www.snort.org/dl/current/snort-2.4.3.tar.gz.
Thanks,
Jennifer
Sam Evans wrote:
> Jennifer,
> =20
> I might be missing something, but when I click the=20
> http://www.snort.org/dl/ link all I see is the 2.4.2 version, not the
2.4.3.
> =20
> Thanks,
> Sam
>=20
>=20
> =20
> On 10/18/05, *Jennifer Steffens* <jennifer...@sourcefire.com=20
> <mailto:jennifer...@sourcefire.com>> wrote:
>=20
> Subject: Fix and Mitigation Available for Snort Vulnerability
>=20
> The Sourcefire Vulnerability Research Team (VRT) has learned of a
> vulnerability in Snort v2.4.0 and higher. Users are only
vulnerable if
> the Back Orifice preprocessor is enabled. Snort v2.4.3 has been
released
> to correct the issue and detailed instructions for mitigating the
issue
> by disabling the Back Orifice preprocessor are below.
>=20
>=20
> Snort v2.4.3
>=20
> In addition to fixing the vulnerability, this version includes a
> mechanism to detect exploits against vulnerable sensors and,
optionally
> for inline sensors, drop the offending traffic. These features
enable a
> phased approach to upgrading while protecting unpatched sensors.
> Detection capabilities are part of the new preprocessor and
therefore
> are available to all users regardless of subscription status.
>=20
> In addition to the source tarball, postgres, mysql and plain RPMs
and a
> win32 installer are available at http://www.snort.org/dl. Please
> remember that updated rules are only included in major releases.
For
> updated rules, visit http://www.snort.org/rules/.
>=20
>=20
> Mitigation Instructions:
>=20
> The Back Orifice preprocessor can be disabled by commenting out
the line
> "preprocessor bo" in snort.conf. This can be done in any text
editor
> using the following procedure:
>=20
> 1. Locate the line "preprocessor bo"
> 2. Comment out this line by preceding it with a hash (#). The new
line
> will look like "#preprocessor bo"
> 3. Save the file
> 4. Restart snort
>=20
>=20
> Background:
>=20
> On Thursday, October 13th Sourcefire was contacted by USCERT with
news
> of a vulnerability in Snort. We used the subsequent days to verify
the
> vulnerability and to prepare mitigation strategies and the
software
> updates necessary to fix the vulnerability for both Sourcefire
customers
> and Snort users. While it cannot be said that no other problems
will
> ever be found in the Snort code base, we can state that we will
> redouble
> our efforts to ensure the security of the system so many people
have
> come to rely on for the detection of network-based threats.
Sourcefire
> will also continue to work with the most sophisticated testing
> facilities in the industry to assure that every reasonable step is
> being
> taken to provide the most secure code base possible.
>=20
>=20
> Technical Details:
> The Back Orifice preprocessor contains a stack-based buffer
overflow.
> This vulnerability could be leveraged by an attacker to execute
code
> remotely on a Snort sensor where the Back Orifice preprocessor is
> enabled. However, there are a number of factors that make remote
code
> execution difficult to achieve across different builds of Snort on
> different platforms, even on the same platform with different
compiler
> versions, and it is more likely that an attacker could use the
> vulnerability as a denial of service attack.
>=20
>=20
> If you have any questions, please let us know at
> snort...@sourcefire.com <mailto:snort...@sourcefire.com>
>=20
> Thanks,
> Jennifer
>=20
>=20
> --
> Jennifer S. Steffens
> Director, Snort Product Management | Sourcefire, Inc.
> W: 410.423.1930 | C: 202.409.7707
> www.sourcefire.com <http://www.sourcefire.com> | www.snort.org
> <http://www.snort.org>
>=20
>=20
> -------------------------------------------------------
> This SF.Net email is sponsored by:
> Power Architecture Resource Center: Free content, downloads,
> discussions,
> and more. http://solutions.newsforge.com/ibmarch.tmpl
> _______________________________________________
> Snort-users mailing list
> Snort...@lists.sourceforge.net
> <mailto:Snort...@lists.sourceforge.net>
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> <https://lists.sourceforge.net/lists/listinfo/snort-users>
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users
>=20
>=20
-------------------------------------------------------
This SF.Net email is sponsored by:
Power Architecture Resource Center: Free content, downloads,
discussions,
and more. http://solutions.newsforge.com/ibmarch.tmpl
_______________________________________________
Snort-users mailing list
Snort...@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users
Thanks, like I said, I think the problem was on my end (and it was).
On 10/18/05, Ron Jenkins <rjen...@dibr.net> wrote:
>
> I see it too.
>
> -----Original Message-----
> From: snort-us...@lists.sourceforge.net
> [mailto:snort-us...@lists.sourceforge.net] On Behalf Of Jennifer
> Steffens
> Sent: Tuesday, October 18, 2005 5:31 PM
> To: Sam Evans
> Cc: snort-users @ lists. sourceforge. net
> Subject: Re: [Snort-users] Fixes and Mitigation Instructions Available
> for Snort Back Orifice Vulnerability
>
> Sam,
>
> Can you try refreshing the page? The 2.4.3 version is there for me. The
> actual link is http://www.snort.org/dl/current/snort-2.4.3.tar.gz.
>
> Thanks,
> Jennifer
>
> Sam Evans wrote:
> > Jennifer,
> >
> > I might be missing something, but when I click the
> > http://www.snort.org/dl/ link all I see is the 2.4.2 version, not the
> 2.4.3.
> >
> > Thanks,
> > Sam
> >
> >
> >
> > On 10/18/05, *Jennifer Steffens* <jennifer...@sourcefire.com
> > <mailto:jennifer...@sourcefire.com>> wrote:
> >
> > Subject: Fix and Mitigation Available for Snort Vulnerability
> >
> > The Sourcefire Vulnerability Research Team (VRT) has learned of a
> > vulnerability in Snort v2.4.0 and higher. Users are only
> vulnerable if
> > the Back Orifice preprocessor is enabled. Snort v2.4.3 has been
> released
> > to correct the issue and detailed instructions for mitigating the
> issue
> > by disabling the Back Orifice preprocessor are below.
> >
> >
> > Snort v2.4.3
> >
> > In addition to fixing the vulnerability, this version includes a
> > mechanism to detect exploits against vulnerable sensors and,
> optionally
> > for inline sensors, drop the offending traffic. These features
> enable a
> > phased approach to upgrading while protecting unpatched sensors.
> > Detection capabilities are part of the new preprocessor and
> therefore
> > are available to all users regardless of subscription status.
> >
> > In addition to the source tarball, postgres, mysql and plain RPMs
> and a
> > win32 installer are available at http://www.snort.org/dl. Please
> > remember that updated rules are only included in major releases.
> For
> > updated rules, visit http://www.snort.org/rules/.
> >
> >
> > Mitigation Instructions:
> >
> > The Back Orifice preprocessor can be disabled by commenting out
> the line
> > "preprocessor bo" in snort.conf. This can be done in any text
> editor
> > using the following procedure:
> >
> > 1. Locate the line "preprocessor bo"
> > 2. Comment out this line by preceding it with a hash (#). The new
> line
> > will look like "#preprocessor bo"
> > 3. Save the file
> > 4. Restart snort
> >
> >
> > Background:
> >
> > On Thursday, October 13th Sourcefire was contacted by USCERT with
> news
> > of a vulnerability in Snort. We used the subsequent days to verify
> the
> > vulnerability and to prepare mitigation strategies and the
> software
> > updates necessary to fix the vulnerability for both Sourcefire
> customers
> > and Snort users. While it cannot be said that no other problems
> will
> > ever be found in the Snort code base, we can state that we will
> > redouble
> > our efforts to ensure the security of the system so many people
> have
> > come to rely on for the detection of network-based threats.
> Sourcefire
> > will also continue to work with the most sophisticated testing
> > facilities in the industry to assure that every reasonable step is
> > being
> > taken to provide the most secure code base possible.
> >
> >
> > Technical Details:
> > The Back Orifice preprocessor contains a stack-based buffer
> overflow.
> > This vulnerability could be leveraged by an attacker to execute
> code
> > remotely on a Snort sensor where the Back Orifice preprocessor is
> > enabled. However, there are a number of factors that make remote
> code
> > execution difficult to achieve across different builds of Snort on
> > different platforms, even on the same platform with different
> compiler
> > versions, and it is more likely that an attacker could use the
> > vulnerability as a denial of service attack.
> >
> >
> > If you have any questions, please let us know at
> > snort...@sourcefire.com <mailto:snort...@sourcefire.com>
> >
> > Thanks,
> > Jennifer
> >
> >
> > --
> > Jennifer S. Steffens
> > Director, Snort Product Management | Sourcefire, Inc.
> > W: 410.423.1930 | C: 202.409.7707
> > www.sourcefire.com <http://www.sourcefire.com> <
> http://www.sourcefire.com> | www.snort.org <http://www.snort.org>
> > <http://www.snort.org>
> >
> >
> > -------------------------------------------------------
> > This SF.Net email is sponsored by:
> > Power Architecture Resource Center: Free content, downloads,
> > discussions,
> > and more. http://solutions.newsforge.com/ibmarch.tmpl
> > _______________________________________________
> > Snort-users mailing list
> > Snort...@lists.sourceforge.net
> > <mailto:Snort...@lists.sourceforge.net>
> > Go to this URL to change user options or unsubscribe:
> > https://lists.sourceforge.net/lists/listinfo/snort-users
> > <https://lists.sourceforge.net/lists/listinfo/snort-users>
> > Snort-users list archive:
> > http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users
> >
> >
>
>
> -------------------------------------------------------
> This SF.Net email is sponsored by:
> Power Architecture Resource Center: Free content, downloads,
> discussions,
> and more. http://solutions.newsforge.com/ibmarch.tmpl
> _______________________________________________
> Snort-users mailing list
> Snort...@lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users
>
------=_Part_30698_24809211.1129681883912
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline
Thanks, like I said, I think the problem was on my end (and it was).<=
br>
<br>
<br><br><div><span class=3D"gmail_quote">On 10/18/05, <b class=3D"gmail_sen=
dername">Ron Jenkins</b> <<a href=3D"mailto:rjen...@dibr.net">rjenkins@=
dibr.net</a>> wrote:</span><blockquote class=3D"gmail_quote" style=3D"bo=
rder-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding=
-left: 1ex;">
I see it too.<br><br>-----Original Message-----<br>From: <a href=3D"mailto:=
snort-us...@lists.sourceforge.net">snort-us...@lists.sourceforg=
e.net</a><br>[mailto:<a href=3D"mailto:snort-us...@lists.sourceforge.=
net">
snort-us...@lists.sourceforge.net</a>] On Behalf Of Jennifer<br>Steff=
ens<br>Sent: Tuesday, October 18, 2005 5:31 PM<br>To: Sam Evans<br>Cc: snor=
t-users @ lists. sourceforge. net<br>Subject: Re: [Snort-users] Fixes and M=
itigation Instructions Available
<br>for Snort Back Orifice Vulnerability<br><br>Sam,<br><br>Can you try ref=
reshing the page? The 2.4.3 version is there for me. The<br>actual link is =
<a href=3D"http://www.snort.org/dl/current/snort-2.4.3.tar.gz">http://www.s=
nort.org/dl/current/snort-2.4.3.tar.gz
</a>.<br><br>Thanks,<br>Jennifer<br><br>Sam Evans wrote:<br>> Jennifer,<=
br>><br>> I might be missing something, but when I click the<br>> =
<a href=3D"http://www.snort.org/dl/">http://www.snort.org/dl/</a> link all =
I see is the=20
2.4.2 version, not the<br>2.4.3.<br>><br>> Thanks,<br>> Sam<br>>=
;<br>><br>><br>> On 10/18/05, *Jennifer Steffens* <<a href=3D"m=
ailto:jennifer...@sourcefire.com">jennifer...@sourcefire.com</a=
>
<br>> <mailto:<a href=3D"mailto:jennifer...@sourcefire.com">jen=
nifer.s...@sourcefire.com</a>>> wrote:<br>><br>>  =
; Subject: Fix and Mitigation Available for Snort Vulnerability=
<br>><br>> The Sourcefire Vulnerability Resea=
rch Team (VRT) has learned of a
<br>> vulnerability in Snort v2.4.0 and higher. =
Users are only<br>vulnerable if<br>> the Back Or=
ifice preprocessor is enabled. Snort v2.4.3 has been<br>released<br>>&nb=
sp; to correct the issue and detailed instructions for mi=
tigating the
<br>issue<br>> by disabling the Back Orifice pre=
processor are below.<br>><br>><br>> Snort =
v2.4.3<br>><br>> In addition to fixing the vu=
lnerability, this version includes a<br>> mechan=
ism to detect exploits against vulnerable sensors and,
<br>optionally<br>> for inline sensors, drop the=
offending traffic. These features<br>enable a<br>> &nb=
sp; phased approach to upgrading while protecting unpatched sensors.<br>>=
; Detection capabilities are part of the new prepro=
cessor and
<br>therefore<br>> are available to all users re=
gardless of subscription status.<br>><br>> In=
addition to the source tarball, postgres, mysql and plain RPMs<br>and a<br=
>> win32 installer are available at=20
<a href=3D"http://www.snort.org/dl">http://www.snort.org/dl</a>. Please<br>=
> remember that updated rules are only included =
in major releases.<br>For<br>> updated rules, vi=
sit <a href=3D"http://www.snort.org/rules/">
http://www.snort.org/rules/</a>.<br>><br>><br>> &=
nbsp; Mitigation Instructions:<br>><br>> The =
Back Orifice preprocessor can be disabled by commenting out<br>the line<br>=
> "preprocessor bo" in=20
snort.conf. This can be done in any text<br>editor<br>>  =
; using the following procedure:<br>><br>> &nb=
sp; 1. Locate the line "preprocessor bo"<br>>  =
; 2. Comment out this line by preceding it with a hash (#). The new
<br>line<br>> will look like "#preprocessor=
bo"<br>> 3. Save the file<br>> &nb=
sp; 4. Restart snort<br>><br>><br>> &=
nbsp; Background:<br>><br>> On Thursday, Octo=
ber 13th Sourcefire was contacted by USCERT with
<br>news<br>> of a vulnerability in Snort. We us=
ed the subsequent days to verify<br>the<br>> vul=
nerability and to prepare mitigation strategies and the<br>software<br>>=
updates necessary to fix the vulnerability for bot=
h Sourcefire
<br>customers<br>> and Snort users. While it can=
not be said that no other problems<br>will<br>> =
ever be found in the Snort code base, we can state that we will<br>>&nbs=
p; redouble<br>> our efforts t=
o ensure the security of the system so many people
<br>have<br>> come to rely on for the detection =
of network-based threats.<br>Sourcefire<br>> wil=
l also continue to work with the most sophisticated testing<br>> &n=
bsp; facilities in the industry to assure that every reasonable=
step is
<br>> being<br>> take=
n to provide the most secure code base possible.<br>><br>><br>>&nb=
sp; Technical Details:<br>> Th=
e Back Orifice preprocessor contains a stack-based buffer<br>overflow.<br>&=
gt; This vulnerability could be leveraged by an att=
acker to execute
<br>code<br>> remotely on a Snort sensor where t=
he Back Orifice preprocessor is<br>> enabled.&nb=
sp; However, there are a number of factors that make remote<br>code<br=
>> execution difficult to achieve across differe=
nt builds of Snort on
<br>> different platforms, even on the same plat=
form with different<br>compiler<br>> versions, a=
nd it is more likely that an attacker could use the<br>> &nbs=
p; vulnerability as a denial of service attack.<br>
><br>><br>> If you have any questions, ple=
ase let us know at<br>> <a href=3D"mailto:snort-=
te...@sourcefire.com">snort...@sourcefire.com</a> <mailto:<a href=3D"ma=
ilto:snort...@sourcefire.com">snort...@sourcefire.com
</a>><br>><br>> Thanks,<br>>  =
; Jennifer<br>><br>><br>> --<b=
r>> Jennifer S. Steffens<br>> &nbs=
p; Director, Snort Product Management | Sourcefire, Inc.<br>> =
; W: 410.423.1930 | C:=20
202.409.7707<br>> <a href=3D"http://www.sourcefi=
re.com">www.sourcefire.com</a> <<a href=3D"http://www.sourcefire.com">ht=
tp://www.sourcefire.com</a>> | <a href=3D"http://www.snort.org">www.snor=
t.org</a><br>> <
<a href=3D"http://www.snort.org">http://www.snort.org</a>><br>><br>&g=
t;<br>> ----------------------------------------=
---------------<br>> This SF.Net email is sponso=
red by:<br>> Power Architecture Resource Center:=
Free content, downloads,
<br>> discussions,<br>> &nbs=
p; and more. <a href=3D"http://solutions.newsforge.com/ibmarch.tmpl">http:/=
/solutions.newsforge.com/ibmarch.tmpl</a><br>> _=
______________________________________________<br>> &nb=
sp; Snort-users mailing list
<br>> <a href=3D"mailto:Snort...@lists.source=
forge.net">Snort...@lists.sourceforge.net</a><br>> &=
nbsp; <mailto:<a href=3D"mailto:Snort...@lists.sourceforge.net">Snort=
-us...@lists.sourceforge.net</a>><br>
> Go to this URL to change user options or unsub=
scribe:<br>> <a href=3D"https://lists.sourceforg=
e.net/lists/listinfo/snort-users">https://lists.sourceforge.net/lists/listi=
nfo/snort-users</a><br>> <<a href=3D"https://=
lists.sourceforge.net/lists/listinfo/snort-users">
https://lists.sourceforge.net/lists/listinfo/snort-users</a>><br>>&nb=
sp; Snort-users list archive:<br>> &n=
bsp; <a href=3D"http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users"=
>http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users
</a><br>><br>><br><br><br>-------------------------------------------=
------------<br>This SF.Net email is sponsored by:<br>Power Architecture Re=
source Center: Free content, downloads,<br>discussions,<br>and more. <a hre=
f=3D"http://solutions.newsforge.com/ibmarch.tmpl">
http://solutions.newsforge.com/ibmarch.tmpl</a><br>________________________=
_______________________<br>Snort-users mailing list<br><a href=3D"mailto:Sn=
ort-...@lists.sourceforge.net">Snort...@lists.sourceforge.net</a><br>
Go to this URL to change user options or unsubscribe:<br><a href=3D"https:/=
/lists.sourceforge.net/lists/listinfo/snort-users">https://lists.sourceforg=
e.net/lists/listinfo/snort-users</a><br>Snort-users list archive:<br><a hre=
f=3D"http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users">
http://www.geocrawler.com/redir-sf.php3?list=3Dsnort-users</a><br></blockqu=
ote></div><br>
------=_Part_30698_24809211.1129681883912--