PROTOCOL-POP -- Snort has detected traffic that may indicate the presence of the pop protocol or vulnerabilities in the pop protocol on the network.
PROTOCOL-POP USER overflow attempt
This rule looks for overly long USER commands in POP messages.
This rule fires on attempts to exploit buffer overflow vulnerabilities in POP servers.
No public information
Known false positives, with the described conditions
This rule fires on USER commands larger than 50 bytes in POP messages.
Cisco Talos Intelligence Group
Vulnerability::Severity::Medium
Vulnerability::Severity::Critical
Vulnerability::Severity::High
MITRE::ATT&CK Framework::Enterprise::Privilege Escalation::Exploitation for Privilege Escalation
Buffer Overflow
Buffer Overflows occur when a memory location is filled past its expected boundaries. Computer attackers target systems without proper terminating conditions on buffers, which then write the additional information in other locations in memory, overwriting what is there. This could corrupt the data, making the system behave erratically or crash. The new information could include malicious executable code, which might be executed.
CVE-2006-2502 |
Loading description
|
CVE-2006-4364 |
Loading description
|
CVE-1999-0494 |
Loading description
|
CVE-2002-1781 |
Loading description
|
CVE-2007-4646 |
Loading description
|