Vulnerability record · CVE-2006-5276 · published 20 February 2007
CVE-2006-5276: Snort DCE/RPC Preprocessor Stack Buffer Overflow via SMB
Snort · Snort
The DCE/RPC preprocessor in Snort (before 2.6.1.3 and 2.7 before beta 2) and Sourcefire Intrusion Sensor contains a stack-based buffer overflow. Crafted SMB traffic can overflow the stack, allowing remote code execution. Because the flaw sits in the detection engine itself, it turns the IDS/IPS sensor into an attack target.
Description
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0 with network reachability, no authentication, and public exploit code makes this a high-risk pre-auth RCE in a security-critical component.
What it is
The DCE/RPC preprocessor in Snort (before 2.6.1.3 and 2.7 before beta 2) and Sourcefire Intrusion Sensor contains a stack-based buffer overflow. Crafted SMB traffic can overflow the stack, allowing remote code execution. Because the flaw sits in the detection engine itself, it turns the IDS/IPS sensor into an attack target.
Impact
A remote attacker can execute arbitrary code in the context of the Snort or Sourcefire sensor process, potentially gaining control of the monitoring host. This can also be used to blind or disable the intrusion detection capability.
Attack surface
Reachable over the network via crafted SMB traffic processed by the DCE/RPC preprocessor; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any sensor with the DCE/RPC preprocessor enabled and exposed to SMB traffic is in scope.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.793, 99.6th percentile) and a public Exploit-DB entry (3362) exists, indicating mature public exploit code. No ransomware group usage is documented.
What to do
- Upgrade Snort to 2.6.1.3 or later, or 2.7 beta 2 or later, and apply the corresponding Sourcefire Intrusion Sensor fix.
- If immediate patching is not possible, disable the DCE/RPC preprocessor or restrict SMB traffic reaching the sensor.
- Segment and firewall sensor management/monitoring interfaces so they are not reachable from untrusted networks.
- Apply vendor and distribution advisories (Red Hat, Fedora, Gentoo, Nortel) for packaged Snort builds.
- Run the sensor with least privilege and isolate it from sensitive internal networks.
Detection
- Monitor sensor process crashes or restarts, especially correlated with inbound SMB (TCP 445/139) traffic.
- Inspect SMB traffic to the sensor for malformed or oversized DCE/RPC preprocessor payloads.
- Alert on unexpected outbound connections or process execution originating from the IDS/IPS host.
- Review Snort/Sourcefire logs for preprocessor errors or anomalies preceding a crash.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5276 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5276), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.