Vulnerability Report

CVE-2005-3252

Title: Sourcefire Snort

Memory Corruption

Proof Of Concept

PoC Available for CVE-2005-3252

CWE Category NVD-CWE-noinfo
Published Date Oct 18, 2005
Modified Date Jun 16, 2026
Exploit Status Available
Score 7.5 CVSS v2.0
Exploit Probability (EPSS)
83.62%

Vulnerability Summary

CVE-2005-3252: Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code via a crafted UDP packet.

Impacted Vendors

Reference Links

http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0505.html http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0010.html http://secunia.com/advisories/17220 http://secunia.com/advisories/17255 http://secunia.com/advisories/17559 http://securitytracker.com/id?1015070 http://www.kb.cert.org/vuls/id/175500 http://www.osvdb.org/20034 http://www.securityfocus.com/bid/15131 http://www.snort.org/docs/change_logs/2.4.3/Changelog.txt http://www.us-cert.gov/cas/techalerts/TA05-291A.html http://www.vupen.com/english/advisories/2005/2138 http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=362187&RenditionID= http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=363396&RenditionID= http://xforce.iss.net/xforce/alerts/id/207 http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0505.html http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0010.html http://secunia.com/advisories/17220 http://secunia.com/advisories/17255 http://secunia.com/advisories/17559 http://securitytracker.com/id?1015070 http://www.kb.cert.org/vuls/id/175500 http://www.osvdb.org/20034 http://www.securityfocus.com/bid/15131 http://www.snort.org/docs/change_logs/2.4.3/Changelog.txt http://www.us-cert.gov/cas/techalerts/TA05-291A.html http://www.vupen.com/english/advisories/2005/2138 http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=362187&RenditionID= http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=363396&RenditionID= http://xforce.iss.net/xforce/alerts/id/207
CVSS v2.0
Source Entity [email protected]
Severity HIGH
7.5
Access Vector
N/A
Authentication
N/A
RAW VECTOR AV:N/AC:L/Au:N/C:P/I:P/A:P

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2005-3252 Exploits & PoCs (Proof Of Concept)

Exploit-DB https://www.exploit-db.com/exploits/10026
View Code
Exploit-DB https://www.exploit-db.com/exploits/1272
View Code
Exploit-DB https://www.exploit-db.com/exploits/1314
View Code
Exploit-DB https://www.exploit-db.com/exploits/16834
View Code
Exploit-DB https://www.exploit-db.com/exploits/1313
View Code
MODIFIED

Vulnerability data updated via NVD.

MODIFIED

Vulnerability data or affected products updated.

PUBLISHED

Vulnerability first announced in NVD.

Attack Vector Matrix

Access Vector N/A
Complexity N/A
Privileges N/A
Interaction NONE
CVSS Vector String AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected Stack

No specific products linked.