Rule Category

FILE-EXECUTABLE -- Snort detected traffic targeting vulnerabilites that are found in or delivered through executable files, regardless of platform. In those instances, Snort is able to correct traffic that has been altered.

Alert Message

FILE-EXECUTABLE Binutils objdump integer overflow attempt

Rule Explanation

This event is generated when an attacker attempts to exploit a denial of service vulnerability present in GNU Binutils 2.30. Impact: Denial of service Details: Rule checks for an attempt to trigger an integer overflow in objdump.c of GNU Binutils 2.30. Ease of Attack: Simple; PoC publicly available

What To Look For

No information provided

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

No rule groups

CVE

Rule Vulnerability

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2018-6543
Loading description