Vulnerability record · CVE-2005-3252 · published 18 October 2005
CVE-2005-3252: Snort Back Orifice preprocessor stack buffer overflow via crafted UDP packet
SSourcefire · Snort
Snort before 2.4.3 contains a stack-based buffer overflow in its Back Orifice (BO) preprocessor. A crafted UDP packet triggers the overflow, allowing remote code execution on the host running the IDS. Because Snort is a network sensor, the flaw turns the monitoring tool itself into an attack target.
Description
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code via a crafted UDP packet.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe vulnerability allows unauthenticated remote code execution on a network sensor, and EPSS indicates a high likelihood of exploitation, though no KEV listing or public exploit references are present.
What it is
Snort before 2.4.3 contains a stack-based buffer overflow in its Back Orifice (BO) preprocessor. A crafted UDP packet triggers the overflow, allowing remote code execution on the host running the IDS. Because Snort is a network sensor, the flaw turns the monitoring tool itself into an attack target.
Impact
An attacker can execute arbitrary code with the privileges of the Snort process, potentially gaining a foothold on the sensor host. This can lead to full compromise of the monitoring system and any data or credentials it holds.
Attack surface
The flaw is reached over the network via a crafted UDP packet processed by the BO preprocessor. No authentication or user interaction is required, as indicated by the AV:N/AC:L/Au:N vector.
Exploitation
The record does not list this CVE in CISA KEV, and no reference tags indicate public exploit code. EPSS shows a high 30-day probability (0.836) and a 99.7th percentile score, suggesting elevated exploitation likelihood despite the absence of KEV listing.
What to do
- Upgrade Snort to version 2.4.3 or later, which contains the fix.
- If immediate upgrade is not possible, disable the Back Orifice preprocessor until patching can be completed.
- Restrict network exposure of Snort sensor interfaces to only required traffic and trusted sources.
- Monitor vendor advisories and apply any additional patches or workarounds from Sourcefire or CERT.
- Run Snort with least privilege to limit the impact of a successful exploit.
Detection
- Inspect Snort or IDS logs for crashes, restarts, or abnormal behavior in the BO preprocessor.
- Monitor network traffic for crafted UDP packets targeting the BO preprocessor port or signature.
- Check host processes for unexpected child processes or code execution originating from the Snort service.
- Review system logs for signs of exploitation attempts against the sensor host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-3252 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-3252), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.