Back to Database
Status published
Medium
CVE-2006-2769
The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4...
Vulnerability Description
The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2769
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/archive/1/435872/100/0/threaded
- http://www.securityfocus.com/archive/1/435734/100/0/threaded
- http://www.demarc.com/support/downloads/patch_20060531
- http://secunia.com/advisories/20766
- http://www.securityfocus.com/bid/18200
- http://secunia.com/advisories/20413
- http://www.securityfocus.com/archive/1/435600/100/0/threaded
- http://www.vupen.com/english/advisories/2006/2119
- http://securityreason.com/securityalert/1018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26855
- http://www.osvdb.org/25837
- http://lists.suse.com/archive/suse-security-announce/2006-Jun/0008.html
- http://securitytracker.com/id?1016191
- http://marc.info/?l=snort-devel&m=114909074311462&w=2
- http://www.snort.org/pub-bin/snortnews.cgi#431
- http://www.securityfocus.com/archive/1/435797/100/0/threaded
More from sourcefire
View All →CVE-2010-2306
The default installation of Sourcefire 3D Sensor 1000, 2000, and...
Medium
4.3
CVE-2009-2344
The web-based management interfaces in Sourcefire Defense Center (DC) and...
Critical
9
CVE-2006-0839
The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly...
Medium
5
CVE-2005-3252
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for...
High
7.5
CVE-2004-2652
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when...
High
7.8
Affected Vendor
sourcefire
View all reports →Affected Software
snort
Vulnerable Versions:
2.4, 2.4.1, 2.4.2, 2.4.3, 2.4.4
Timeline
Official Publish:
June 2nd, 2006
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.