CVE-2008-1804
snort - rules bypass
EPSS 0.26%
Description
preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, which allows remote attackers to bypass detection rules by using a different TTL for each fragment.
How to fix CVE-2008-1804
To remediate CVE-2008-1804, upgrade the affected package to a fixed version below.
- Debian/snort—upgrade to 2.7.0-20 or later
- Debian/snort—upgrade to 2.7.0-19+lenny1 or later
Is CVE-2008-1804 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.7.0-20
- from 0, < 2.7.0-19+lenny1