CVE-2006-5276
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 79%
from disclosure to weapon9 days
Published on NVDFeb 20
1st PoC+9d
metasploitFeb 19
exploitation probability
79%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.
Affected products
n/a · n/apublic PoCs found — 4✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/3609cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/3362exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/18723exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/3391⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://fedoranews.org/updates/FEDORA-2007-206.shtmlhttp://iss.net/threats/257.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=229265http://secunia.com/advisories/24190http://secunia.com/advisories/24235http://secunia.com/advisories/24239http://secunia.com/advisories/24240http://secunia.com/advisories/24272http://secunia.com/advisories/26746http://security.gentoo.org/glsa/glsa-200703-01.xmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/31275https://www.exploit-db.com/exploits/3362