iss.snort-rpc.txt...

- AV AC AU C I A
发布: 2003-03-10
修订: 2025-04-13

ISS Security Advisory - Snort v1.8 through 1.9.0 contains a remote root vulnerability in the processing of fragmented RPC traffic. Since fragment sizes are not properly checked against the remaining buffer space, remote attackers can execute arbitrary code as root by sending a packet to any IP in network space a snort sensor is listening to. Successful exploitation does not generate log entries, and non-executable stacks do not offer protection.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息