Back to Rule

Rule History

SID: 10002473 • Source: ptrules/open

Versions (6)

Version DetailsCurrent

Rev: 1Jul 24, 2025, 5:44 PM

ATTACK [PTsecurity] Possible Dnsmasq <2.78 DHCPv6 Link Layer Address Stack Overflow (CVE-2017-14493)

alert udp any any -> any 547 (msg:"ATTACK [PTsecurity] Possible Dnsmasq <2.78 DHCPv6 Link Layer Address Stack Overflow (CVE-2017-14493)"; flow:no_stream; content:"|0C|"; depth:1; content:"|00 4F|"; distance:33; within:2; byte_test:2, >, 16, 0, relative, big; isdataat:18,relative; reference:cve, 2017-14493; reference:url, security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html; reference:url, rules.ptsecurity.com; classtype:attempted-admin; sid:10002473; rev:1;)

Jul 24, 2025, 5:44 PM

Jul 24, 2025, 5:44 PM

Oct 16, 2025, 10:34 AM

Oct 16, 2025, 10:34 AM

rules/ptopen-attacks.rules