13840.txt
来自「This is the snapshot of Snot Latest Rule」· 文本 代码 · 共 74 行
TXT
74 行
Rule--Sid13840--Summary:This event is generated when an attempt is made to exploit a known vulnerability in Interbase.--Impact:Denial of Service. Information disclosure. Loss of integrity. Complete admin access.--Detailed Information:Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0.257, allow remote attackers to execute arbitrary code via (1) a long service attach request on TCP port 3050 to the (a) SVC_attach or (b) INET_connect function, (2) a long create request on TCP port 3050 to the (c) isc_create_database or (d) jrd8_create_database function, (3) a long attach request on TCP port 3050 to the (e) isc_attach_database or (f) PWD_db_aliased function, or unspecified vectors involving the (4) jrd8_attach_database or (5) expand_filename2 function.--Affected Systems:Borland Software Interbase LI 8.0.0.253Borland Software Interbase LI 8.0.0.53Borland Software Interbase LI 8.0.0.54Borland Software Interbase WI 5.1.1.680Borland Software Interbase WI 8.1.0.257Borland Software Interbase WI-O6.0.1.6Borland Software Interbase WI-O6.0.2.0Borland Software Interbase WI-V5.1.1.680Borland Software Interbase WI-V5.5.0.742Borland Software Interbase WI-V6.0.0.627Borland Software Interbase WI-V6.0.1.0Borland Software Interbase WI-V6.0.1.6Borland Software Interbase WI-V6.5.0.28Borland Software Interbase WI-V7.0.1.1Borland Software Interbase WI-V7.5.0.129Borland Software Interbase WI-V7.5.1.80Borland Software Interbase WI-V8.0.0.123--Attack Scenarios:--Ease of Attack:--False Positives:None known.--False Negatives:None known.--Corrective Action:Upgrade to the latest non-affected version of the software.Apply the appropriate vendor supplied patches.--Contributors:Sourcefire Vulnerability Research TeamThis document was generated from data supplied by the National Vulnerability Database. A product of the National Institute of Standards and Technology.For more information see http://nvd.nist.gov/--Additional References:NIST CVE-2007-5243:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5243--
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?