SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.
SERVER-OTHER X.509 IPAddressFamily extension buffer overread attempt
This event is generated when an attacker attempts to exploit a buffer overread in OpenSSL.
Attempted Information Leak
Rule checks for an attempt to exploit a buffer overread when parsing X.509 certificates with a malformed IPAddressFamily extension.
Ease of Attack:
What To Look For
No public information
No known false positives
Cisco Talos Intelligence Group
MITRE ATT&CK Framework
For reference, see the MITRE ATT&CK vulnerability types here:
CVE Additional Information
CVE-2017-3735While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.
||Ease of Access||