Get a Pentest and security assessment of your IT network.

News

Vulnerabiity Spotlight: Tarantool Denial of Service Vulnerabilities

Talos is disclosing two denial of service vulnerabilities in Tarantool. Tarantool is an open-source lua-based application server. Talos disclosing two vulnerabilities (CVE-2016-9036 & CVE-16-9037) Tarantool’s protocol is based around the MsgPack serialization format. A specially crafted packet can cause the mp_check function to incorrectly return success when trying to check if decoding a map16 packet will read outside the bounds of a buffer. The following Snort Rules will detect exploitation attempts.”]

Source: https://blog.talosintelligence.com/2016/12/tarantool-DoS.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin