Australian IT JOBS : Sydney IT jobs, UNIX jobs, Linux jobs, Java jobs, ASP jobs Linux.conf.au Linux.conf.au
Technology news and Jobs arrow Information Technology News arrow Bug in security software enables remote attack
Bug in security software enables remote attack PDF Print E-mail
Written by Stephen Withers   
Thursday, 22 February 2007
A buffer overflow vulnerability in Snort, the popular open-source intrusion detection system for Linux and Windows, could lead to the compromise of the system it is running on, security researchers have warned.

The flaw was reported by IBM Internet Security Systems, which said "Compromise of machines using affected versions of Snort or Sourcefire may lead to exposure of confidential information, loss of productivity, and further compromise.  Successful exploitation of this vulnerability results in remote code execution with the privilege level of Snort, usually root or SYSTEM. Exploitation of this vulnerability does not require user interaction."

The good news is that it hasn't been proven that the vulnerability is actually exploitable, and it has been fixed. The affected versions are Snort 2.6.1, 2.6.1.1, 2.6.1.2, and 2.7 beta 1, and the cure is to update to version 2.6.1.3 or later. Version 2.7 beta 2 will also resolve the issue. Rules have also been released to detect attacks targeting the vulnerability in affected versions.

This isn't the first time that a vulnerability in security software has provided the bad guys with an attack vector. For example, a stack overflow vulnerability in Symantec Client Security and AntiVirus Corporate Edition discovered last year had the potential for arbitrary code execution, and in 2004 a flaw in the firewall included in several Symantec products caused a complete system halt if maliciously formatted TCP packets were received.{moscomment}


Get stories like this delivered daily - FREE - subscribe now
When you subscribe get a 12 months license for LiveProject
Valued at $99 USD


LiveWire - Desktop alerts Download the FREE iTWire desktop alert widget LiveWire - Desktop alerts


Del.icio.us!
 
< Prev   Next >
Contact , Register , Advertise with iTWire , Links , Register , About iTWire , Feedback , Post your jobs , Events , iTWire site map , Start Blogging
Industry Releases , Submit your release now , Start submitting to iTWire , How to post video