Neutralizing Tofsee Spambot – Part 3 | Network-based kill switch
ID: a1a01da0-7013-5258-acab-cdf951d48385
STIX ID: report--a1a01da0-7013-5258-acab-cdf951d48385
Feed Name: The Spamhaus Project
Threat Score
**Executive Summary:** The report details an unbounded-length vulnerability in the CRC32 hash routine used when parsing an InmemoryConfig resource in the Tofsee binary; by crafting a ResourceStructure packet with a manipulated 4-byte len field an attacker can trigger an out-of-bounds read that crashes the process.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
