Executive Summary

Informations
Name CVE-2008-1804 First vendor Publication 2008-05-22
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, which allows remote attackers to bypass detection rules by using a different TTL for each fragment.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1804

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 20

OpenVAS Exploits

Date Description
2009-12-14 Name : Mandriva Security Advisory MDVSA-2009:259-1 (snort)
File : nvt/mdksa_2009_259_1.nasl
2009-10-13 Name : Mandrake Security Advisory MDVSA-2009:259 (snort)
File : nvt/mdksa_2009_259.nasl
2009-02-17 Name : Fedora Update for snort FEDORA-2008-4986
File : nvt/gb_fedora_2008_4986_snort_fc9.nasl
2009-02-17 Name : Fedora Update for snort FEDORA-2008-5001
File : nvt/gb_fedora_2008_5001_snort_fc8.nasl
2009-02-17 Name : Fedora Update for snort FEDORA-2008-5045
File : nvt/gb_fedora_2008_5045_snort_fc7.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
45452 Snort Fragmented IP Packets TTL Traffic Filtering Bypass

Nessus® Vulnerability Scanner

Date Description
2009-10-08 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2009-259.nasl - Type : ACT_GATHER_INFO
2008-06-09 Name : The remote Fedora host is missing a security update.
File : fedora_2008-4986.nasl - Type : ACT_GATHER_INFO
2008-06-09 Name : The remote Fedora host is missing a security update.
File : fedora_2008-5001.nasl - Type : ACT_GATHER_INFO
2008-06-09 Name : The remote Fedora host is missing a security update.
File : fedora_2008-5045.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

http://cvs.snort.org/viewcvs.cgi/snort/ChangeLog?rev=1.534.2.11
http://cvs.snort.org/viewcvs.cgi/snort/src/preprocessors/spp_frag3.c.diff?r1=...
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=701
http://secunia.com/advisories/30348
http://secunia.com/advisories/30563
http://secunia.com/advisories/31204
http://securitytracker.com/id?1020081
http://www.ipcop.org/index.php?name=News&file=article&sid=40
http://www.securityfocus.com/bid/29327
http://www.vupen.com/english/advisories/2008/1602
https://exchange.xforce.ibmcloud.com/vulnerabilities/42584
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00156.html
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00167.html
https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00198.html
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
Date Informations
2024-11-28 23:14:20
  • Multiple Updates
2024-11-28 12:15:25
  • Multiple Updates
2021-05-05 01:04:40
  • Multiple Updates
2021-05-04 12:07:24
  • Multiple Updates
2021-04-22 01:07:48
  • Multiple Updates
2021-01-20 01:04:12
  • Multiple Updates
2020-05-23 01:39:23
  • Multiple Updates
2020-05-23 00:21:34
  • Multiple Updates
2017-08-08 09:24:01
  • Multiple Updates
2016-04-26 17:19:02
  • Multiple Updates
2014-02-17 10:44:39
  • Multiple Updates
2013-05-11 00:15:03
  • Multiple Updates