SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-0251

Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive…

HIGH 7.8EPSS 2.40%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files.

CVSS 2.0
7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS
2.40% probability · 83th percentile
CISA KEV
Not listed
Affected
snort/snort
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.