[Snort-sigs] Sourcefire VRT Certified Rules Update

Sourcefire VRT research at ...435...
Wed Mar 29 16:09:06 EST 2006


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sourcefire VRT Certified Rules Update

Synopsis:
The Sourcefire VRT has learned of vulnerabilities affecting hosts using
Sendmail and has identified additional attack vectors for
vulnerabilities affecting Microsoft HTML Help Workshop.


Details:
A race condition exists in versions of Sendmail, this vulnerability may
allow a remote attacker to execute code of their choosing on an
affected server. A programming error in the way that Sendmail handles
asynchronous signals may allow an attacker to overflow a fixed length
buffer by supplying a large amount of data in an email header.

A rule to detect attacks targeting this vulnerability is included in
this update and is identified as sid 5739.

HTML Help Workshop fails to properly validate file contents before
reading and putting information into a fixed length buffer. A malicious
file may contain information that could overflow the buffer and execute
code on the affected system.

Rules to detect attacks targeting this vulnerability are included in
this update and are identified as sids 5740 and 5741.



New rules:
5739 - SMTP headers too long server response (smtp.rules)
5740 - WEB-CLIENT Microsoft HTML help workshop file .hhp download
attempt (web-client.rules)
5741 - WEB-CLIENT Microsoft HTML help workshop buffer overflow attempt
(web-client.rules)

Updated rules:
5727 - NETBIOS SMB-DS Trans Max Param DOS attempt (netbios.rules)
5728 - NETBIOS SMB-DS Trans unicode Max Param DOS attempt
(netbios.rules)
5729 - NETBIOS SMB Trans unicode Max Param DOS attempt (netbios.rules)
5730 - NETBIOS SMB Trans Max Param DOS attempt (netbios.rules)
5731 - NETBIOS-DG SMB Trans Max Param DOS attempt (netbios.rules)
5732 - NETBIOS-DG SMB Trans unicode Max Param DOS attempt
(netbios.rules)
5733 - NETBIOS SMB-DS Trans andx Max Param DOS attempt (netbios.rules)
5734 - NETBIOS SMB-DS Trans unicode andx Max Param DOS attempt
(netbios.rules)
5735 - NETBIOS SMB Trans unicode andx Max Param DOS attempt
(netbios.rules)
5736 - NETBIOS SMB Trans andx Max Param DOS attempt (netbios.rules)
5737 - NETBIOS-DG SMB Trans andx Max Param DOS attempt (netbios.rules)
5738 - NETBIOS-DG SMB Trans unicode andx Max Param DOS attempt
(netbios.rules)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (Darwin)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFEKyF8Mpm0ve0NhMcRAm74AJ4hXR76gW0yTcLDsduq1WknUKWyngCfW5hc
J5IVEAkZN4u+tRa1wJVssbs=
=xBC6
-----END PGP SIGNATURE-----




More information about the Snort-sigs mailing list