Blog | G5 Cyber Security

Vulnerabiity Spotlight: Tarantool Denial of Service Vulnerabilities

Talos is disclosing two denial of service vulnerabilities in Tarantool. Tarantool is an open-source lua-based application server. Talos disclosing two vulnerabilities (CVE-2016-9036 & CVE-16-9037) Tarantool’s protocol is based around the MsgPack serialization format. A specially crafted packet can cause the mp_check function to incorrectly return success when trying to check if decoding a map16 packet will read outside the bounds of a buffer. The following Snort Rules will detect exploitation attempts.”]

Source: https://blog.talosintelligence.com/2016/12/tarantool-DoS.html

Exit mobile version