An integer underflow issue has been reported in the experimental GRE
protocol decoder. This could present a potential vulnerability or cause
the Snort process to fail. This issue should affect a small minority of
users, because it only exists for users who:
1. Download Snort source code from releases 2.6.1, 2.6.1.1, or 2.6.1.2
AND
2. Configure the build using the --enable-gre option, to enable the
experimental GRE protocol decoder
This issue does not exist for users who do not meet both of these
conditions.
A fix for the issue is in the Snort 2.6.1 development branch. Users who
have built Snort with --enable-gre are advised to recompile Snort
without the --enable-gre feature, or check out the code from the 2.6.1
branch and rebuild it with the --enable-gre feature. Thanks to Chris
Rohlf of Calyptix Security for reporting the issue.
-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
|