Network Security Toolkit (NST) Patch: P200703061 Logo
Detailed Patch README File - Last Updated: 2008-02-28T23:41:42-05:00

Patch Summary: Security patch - updates snort to version: "".

Patch Release Specifications:

Patch Can Be Applied To NST Distribution v1.5.0 - v1.5.0
Patch Type patch
Architecture i386
Can Patch Be Installed On A NST Live CD/DVD yes
Patch Creation Date 2007-03-05
Current Patch Version Number 1.0.2
Patch Download
MD5SUM Checksum 460132fd3f78c7903cf24f5aba309646

Patch Revision History:

2007-03-06 (v1.0.2)
Now includes a new version of "setup_snort" which will correctly identify and use the new security patched snort binary: "v2.6.1.3".

2007-03-06 (v1.0.1)
Patch has been updated to provide support for a "Live CD" boot of the NST as well as a hard disk and virtual machine installation. In this new patch, the new version of snort is placed under /usr/bin/snort, and the version under /usr/local/snort- is replace with a symbolic link to /usr/bin/snort (except in the case of a Live CD). The /etc/rc.d/init.d/snortd script is then updated to use the /usr/bin/snort version.

2007-03-05 (v1.0.0)
This patch installs an updated version of the "snort" executable (version This is to address the following security issue posted at the Snort website: "A remotely exploitable vulnerability exists in the DCE/RPC dynamic preprocessor included with Snort versions 2.6.1,, and 2.7 Beta 1."

Patch Release Notes:

This patch can be applied by hand by downloading the patch file: "" to your NST probe system, unzipping it and then running the "" script contained, For example:

[root@probe ~]# mkdir /tmp/patch
[root@probe ~]# cd /tmp/patch
[root@probe patch]# wget -nH

  ... output from wget ...

[root@probe patch]# unzip

  ... output from unzip ...

[root@probe patch]# ./

  ... output from ...

[root@probe patch]# cd
[root@probe ~]# rm -fr /tmp/patch
[root@probe ~]#