2921.txt

来自「This is the snapshot of Snot Latest Rule」· 文本 代码 · 共 63 行

TXT
63
字号
Rule: --Sid: 2921-- Summary: This event is generated when an inverse query attempt is made using UDP.-- Impact: Possible execution of arbitrary code.--Detailed Information:Bind 8 contains a programming error that may present an attacker withthe opportunity to execute code of their choosing on an affected server.The error occurs in the handling of malformed transactions. When usingUDP this can result in the attacker causing a stack overflow in named.--Affected Systems:	Bind 8.--Attack Scenarios: An attacker needs to send a specially crafted and malformed query to anaffected server.-- Ease of Attack: Moderate.-- False Positives:None known.--False Negatives:None known.-- Corrective Action: Upgrade to the latest non-affected version of the software.Apply the appropriate vendor supplied patches.--Contributors: Sourcefire Vulnerability Research TeamBrian Caswell <bmc@sourcefire.com>Nigel Houghton <nigel.houghton@sourcefire.com>-- Additional References:--

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?