SERVER-MAIL -- Snort has detected traffic exploiting vulnerabilities in mail servers (such as Exchange, Courrier). These are different from protocol traffic, as this deals with the traffic going to the mail server itself.
SERVER-MAIL EHLO user overflow attempt
Rule checks for overly long EHLO SMTP messages used to exploit an off-by-one vulnerability present in the Exim mail transfer agent.
This event is generated when an attacker attempts to send an overly long EHLO SMTP message, used to exploit an off-by-one vulnerability present in the Exim mail transfer agent.
No public information
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
MITRE::ATT&CK Framework::Enterprise::Privilege Escalation::Exploitation for Privilege Escalation
Buffer Overflow
Buffer Overflows occur when a memory location is filled past its expected boundaries. Computer attackers target systems without proper terminating conditions on buffers, which then write the additional information in other locations in memory, overwriting what is there. This could corrupt the data, making the system behave erratically or crash. The new information could include malicious executable code, which might be executed.
CVE-2018-6789 |
Loading description
|
CVE-2019-16928 |
Loading description
|