Eeye IRIS缓冲区溢出漏洞

漏洞信息详情

Eeye IRIS缓冲区溢出漏洞

漏洞简介

eEye IRIS 1.01 beta版本存在漏洞。远程攻击者可以借助大量UDP连接来导致服务拒绝。

漏洞公告

The vendor has provided both a statement on this issue (attached in the ‘Credit’ section) and a work around:
” The problem triggered by this “DoS” seems to result from filling packet buffers faster than Windows can paint them to the screen. If you are really worried about this, until Iris is out of beta and fixes the “problem”, then we recommend you turn off Iris’s Capture packet display feature and use Iris’s decode view instead.”

参考网址

来源: BID
名称: 1627
链接:http://www.securityfocus.com/bid/1627

来源: BUGTRAQ
名称: 20000831 Remote DoS Attack in Eeye Iris 1.01 and SpyNet CaptureNet v3.12
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=96774637326591&w=2

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享