← Vulnerability feed

Vulnerability record · CVE-2006-5276 · published 20 February 2007

CVE-2006-5276: Snort DCE/RPC Preprocessor Stack Buffer Overflow via SMB

Snort · Snort

The DCE/RPC preprocessor in Snort (before 2.6.1.3 and 2.7 before beta 2) and Sourcefire Intrusion Sensor contains a stack-based buffer overflow. Crafted SMB traffic can overflow the stack, allowing remote code execution. Because the flaw sits in the detection engine itself, it turns the IDS/IPS sensor into an attack target.

10.0 CVSS 2.0 High EPSS 79% · top 0.4%
10.0CVSS 2.0 base score
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
48References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0 with network reachability, no authentication, and public exploit code makes this a high-risk pre-auth RCE in a security-critical component.

What it is

The DCE/RPC preprocessor in Snort (before 2.6.1.3 and 2.7 before beta 2) and Sourcefire Intrusion Sensor contains a stack-based buffer overflow. Crafted SMB traffic can overflow the stack, allowing remote code execution. Because the flaw sits in the detection engine itself, it turns the IDS/IPS sensor into an attack target.

Impact

A remote attacker can execute arbitrary code in the context of the Snort or Sourcefire sensor process, potentially gaining control of the monitoring host. This can also be used to blind or disable the intrusion detection capability.

Attack surface

Reachable over the network via crafted SMB traffic processed by the DCE/RPC preprocessor; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any sensor with the DCE/RPC preprocessor enabled and exposed to SMB traffic is in scope.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.793, 99.6th percentile) and a public Exploit-DB entry (3362) exists, indicating mature public exploit code. No ransomware group usage is documented.

What to do

  • Upgrade Snort to 2.6.1.3 or later, or 2.7 beta 2 or later, and apply the corresponding Sourcefire Intrusion Sensor fix.
  • If immediate patching is not possible, disable the DCE/RPC preprocessor or restrict SMB traffic reaching the sensor.
  • Segment and firewall sensor management/monitoring interfaces so they are not reachable from untrusted networks.
  • Apply vendor and distribution advisories (Red Hat, Fedora, Gentoo, Nortel) for packaged Snort builds.
  • Run the sensor with least privilege and isolate it from sensitive internal networks.

Detection

  • Monitor sensor process crashes or restarts, especially correlated with inbound SMB (TCP 445/139) traffic.
  • Inspect SMB traffic to the sensor for malformed or oversized DCE/RPC preprocessor payloads.
  • Alert on unexpected outbound connections or process execution originating from the IDS/IPS host.
  • Review Snort/Sourcefire logs for preprocessor errors or anomalies preceding a crash.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://fedoranews.org/updates/FEDORA-2007-206.shtml
http://iss.net/threats/257.html Vendor Advisory
http://secunia.com/advisories/24190
http://secunia.com/advisories/24235
http://secunia.com/advisories/24239
http://secunia.com/advisories/24240
http://secunia.com/advisories/24272
http://secunia.com/advisories/26746
http://security.gentoo.org/glsa/glsa-200703-01.xml
http://www.kb.cert.org/vuls/id/196240 US Government Resource
http://www.osvdb.org/32094
http://www.securityfocus.com/archive/1/461810/100/0/threaded
http://www.securityfocus.com/bid/22616
http://www.securitytracker.com/id?1017669
http://www.securitytracker.com/id?1017670
http://www.snort.org/docs/advisory-2007-02-19.html Vendor Advisory
http://www.us-cert.gov/cas/techalerts/TA07-050A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2007/0656
http://www.vupen.com/english/advisories/2007/0668
http://www116.nortelnetworks.com/pub/repository/CLARIFY/DOCUMENT/2007/08/021923-01.pdf
http://www130.nortelnetworks.com/go/main.jsp?cscat=BLTNDETAIL&DocumentOID=540173
https://bugzilla.redhat.com/show_bug.cgi?id=229265
https://exchange.xforce.ibmcloud.com/vulnerabilities/31275
https://www.exploit-db.com/exploits/3362
http://fedoranews.org/updates/FEDORA-2007-206.shtml
http://iss.net/threats/257.html Vendor Advisory
http://secunia.com/advisories/24190
http://secunia.com/advisories/24235
http://secunia.com/advisories/24239
http://secunia.com/advisories/24240
http://secunia.com/advisories/24272
http://secunia.com/advisories/26746
http://security.gentoo.org/glsa/glsa-200703-01.xml
http://www.kb.cert.org/vuls/id/196240 US Government Resource
http://www.osvdb.org/32094
http://www.securityfocus.com/archive/1/461810/100/0/threaded
http://www.securityfocus.com/bid/22616
http://www.securitytracker.com/id?1017669
http://www.securitytracker.com/id?1017670
http://www.snort.org/docs/advisory-2007-02-19.html Vendor Advisory

Track CVE-2006-5276 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2003-0033Snort vulnerabilityBuffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC pac…EPSS 12%8.8CVE-2016-1417Snort untrusted search path vulnerabilityUntrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a …EPSS 4.4%7.8CVE-2007-0251Snort vulnerabilityInteger underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locat…EPSS 2.4%7.5CVE-2021-40114Cisco secure firewall management center allocation without limits vulnerabilityMultiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthentica…EPSS 2.4%7.5CVE-2021-1223Cisco secure firewall management center vulnerabilityMultiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass …EPSS 2.0%7.5CVE-2001-0669Cisco catalyst 6000 intrusion detection system module vulnerabilityVarious Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System M…EPSS 4.4%7.1CVE-2007-1398Snort vulnerabilityThe frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, all…EPSS 5.6%6.8CVE-2008-1804Snort vulnerabilitypreprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, which allows …EPSS 2.3%

Source: NIST National Vulnerability Database (record CVE-2006-5276), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.