← Vulnerability feed

Vulnerability record · CVE-2005-3252 · published 18 October 2005

CVE-2005-3252: Snort Back Orifice preprocessor stack buffer overflow via crafted UDP packet

SSourcefire · Snort

Snort before 2.4.3 contains a stack-based buffer overflow in its Back Orifice (BO) preprocessor. A crafted UDP packet triggers the overflow, allowing remote code execution on the host running the IDS. Because Snort is a network sensor, the flaw turns the monitoring tool itself into an attack target.

7.5 CVSS 2.0 High EPSS 84% · top 0.3%
7.5CVSS 2.0 base score
84%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
30References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code via a crafted UDP packet.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe vulnerability allows unauthenticated remote code execution on a network sensor, and EPSS indicates a high likelihood of exploitation, though no KEV listing or public exploit references are present.

What it is

Snort before 2.4.3 contains a stack-based buffer overflow in its Back Orifice (BO) preprocessor. A crafted UDP packet triggers the overflow, allowing remote code execution on the host running the IDS. Because Snort is a network sensor, the flaw turns the monitoring tool itself into an attack target.

Impact

An attacker can execute arbitrary code with the privileges of the Snort process, potentially gaining a foothold on the sensor host. This can lead to full compromise of the monitoring system and any data or credentials it holds.

Attack surface

The flaw is reached over the network via a crafted UDP packet processed by the BO preprocessor. No authentication or user interaction is required, as indicated by the AV:N/AC:L/Au:N vector.

Exploitation

The record does not list this CVE in CISA KEV, and no reference tags indicate public exploit code. EPSS shows a high 30-day probability (0.836) and a 99.7th percentile score, suggesting elevated exploitation likelihood despite the absence of KEV listing.

What to do

  • Upgrade Snort to version 2.4.3 or later, which contains the fix.
  • If immediate upgrade is not possible, disable the Back Orifice preprocessor until patching can be completed.
  • Restrict network exposure of Snort sensor interfaces to only required traffic and trusted sources.
  • Monitor vendor advisories and apply any additional patches or workarounds from Sourcefire or CERT.
  • Run Snort with least privilege to limit the impact of a successful exploit.

Detection

  • Inspect Snort or IDS logs for crashes, restarts, or abnormal behavior in the BO preprocessor.
  • Monitor network traffic for crafted UDP packets targeting the BO preprocessor port or signature.
  • Check host processes for unexpected child processes or code execution originating from the Snort service.
  • Review system logs for signs of exploitation attempts against the sensor host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0505.html
http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0010.html
http://secunia.com/advisories/17220
http://secunia.com/advisories/17255
http://secunia.com/advisories/17559
http://securitytracker.com/id?1015070
http://www.kb.cert.org/vuls/id/175500 PatchThird Party AdvisoryUS Government Resource
http://www.osvdb.org/20034
http://www.securityfocus.com/bid/15131
http://www.snort.org/docs/change_logs/2.4.3/Changelog.txt
http://www.us-cert.gov/cas/techalerts/TA05-291A.html PatchThird Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2005/2138
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=362187&RenditionID=
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=363396&RenditionID=
http://xforce.iss.net/xforce/alerts/id/207 Vendor Advisory
http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0505.html
http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0010.html
http://secunia.com/advisories/17220
http://secunia.com/advisories/17255
http://secunia.com/advisories/17559
http://securitytracker.com/id?1015070
http://www.kb.cert.org/vuls/id/175500 PatchThird Party AdvisoryUS Government Resource
http://www.osvdb.org/20034
http://www.securityfocus.com/bid/15131
http://www.snort.org/docs/change_logs/2.4.3/Changelog.txt
http://www.us-cert.gov/cas/techalerts/TA05-291A.html PatchThird Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2005/2138
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=362187&RenditionID=
http://www130.nortelnetworks.com/cgi-bin/eserv/cs/main.jsp?cscat=BLTNDETAIL&DocumentOID=363396&RenditionID=
http://xforce.iss.net/xforce/alerts/id/207 Vendor Advisory

Track CVE-2005-3252 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2005-3252), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.