SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.
SERVER-OTHER X.509 IPAddressFamily extension buffer overread attempt
This event is generated when an attacker attempts to exploit a buffer overread in OpenSSL. Impact: Attempted Information Leak Details: Rule checks for an attempt to exploit a buffer overread when parsing X.509 certificates with a malformed IPAddressFamily extension. Ease of Attack: Medium
No information provided
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
CVE-2017-3735While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g. |
|