CVE-2016-1417
Severity CVSS v4.0:
Pending analysis
Type:
CWE-426
Untrusted Search Path
Publication date:
23/01/2017
Last modified:
20/04/2025
Description
Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse tcapi.dll that is located in the same folder on a remote file share as a pcap file that is being processed.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:snort:snort:2.9.7.0:*:*:*:*:windows:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://hyp3rlinx.altervista.org/advisories/SNORT-DLL-HIJACK.txt
- http://packetstormsecurity.com/files/138915/Snort-2.9.7.0-WIN32-DLL-Hijacking.html
- http://www.securityfocus.com/archive/1/539579/100/0/threaded
- http://www.securityfocus.com/bid/93269
- http://www.securitytracker.com/id/1036936
- http://hyp3rlinx.altervista.org/advisories/SNORT-DLL-HIJACK.txt
- http://packetstormsecurity.com/files/138915/Snort-2.9.7.0-WIN32-DLL-Hijacking.html
- http://www.securityfocus.com/archive/1/539579/100/0/threaded
- http://www.securityfocus.com/bid/93269
- http://www.securitytracker.com/id/1036936



