Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Sourcefire VRT Certified Rules Update |
|---|---|
| Date: | Fri, 22 Jul 2005 18:22:45 -0400 |
Sourcefire VRT Certified Rules Update
Synopsis: The Sourcefire Vulnerability Research Team (VRT) has learned of serious vulnerabilities affecting Microsoft Windows, RealPlayer, MailEnable, the PHP XML-RPC module and FutureSoft TFTP server.
Details: A programming error in the processing of malformed InfoTech protocol messages used by Microsoft help, can lead to the exposure of a buffer overflow condition. An attacker may be able to overflow this buffer and supply code of their choosing to be executed on the system with the privileges of the administrative account. In addition, applications may treat Windows Help as a trusted program and further exploitation and host firewall bypass may be possible.
Rules to detect attacks against this vulnerability are included in this rule pack and are identified as sids 3819 through 3821.
The RealPlayer media player uses RealText to support streaming text documents. A vulnerability exists in the way RealPlayer handles a malformed request for a .rt file that contains an incorrect RealText version number. If an overly long .rt filename is requested and an incorrect RealText version is specified, a buffer allocated to handle error conditions can be overflowed. This may permit the execution of arbitrary code
Rules to detect attacks against this vulnerability are included in this rule pack and are identified as sids 3822 through 3823.
MailEnable is a Windows-based mail server. A vulnerability exists in the MailEnable SMTP server, possibly allowing a denial of service or the execution of arbitrary code with system privileges.
A Rule to detect attacks against this vulnerability is included in this rule pack and is identified as sid 3824.
A vulnerability exists in the PHP XML-RPC module that may allow unauthorized users to execute arbitrary commands. No user authentication is required to execute these commands.
A Rule to detect attacks against this vulnerability is included in this rule pack and is identified as sid 3827.
A vulnerability exists in the FutureSoft TFTP server when processing overly long read or write requests for either a file name or transfer mode string. This may cause a buffer overflow and the subsequent execution of arbitrary commands on a vulnerable server.
Rules to detect attacks against this vulnerability are included in this rule pack and are identified as sids 3817 through 3818.
Matthew Watchinski Director, Vulnerability Research Sourcefire, Inc.
------------------------------------------------------- SF.Net email is sponsored by: Discover Easy Linux Migration Strategies from IBM. Find simple to follow Roadmaps, straightforward articles, informative Webcasts and more! Get everything you need to get up to speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
|---|---|
| Next by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
| Previous by Thread: | [Snort-sigs] Sourcefire VRT Certified Rules Update, Matthew Watchinski |
| Next by Thread: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
| Indexes: | [Date] [Thread] [Top] [All Lists] |