""ET EXPLOIT Possible CVE-2015-7547 Large Response to A/AAAA query""

SID: 2022547

Revision: 1

Class Type: attempted-user

Metadata: created_at 2016_02_18, cve CVE_2015_7547, updated_at 2016_02_18

Reference:

  • cve

  • 2015-7547

Protocol: tcp

Source Network: any

Source Port: 53

Destination Network: $HOME_NET

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "|00 01|" Depth: 2 Offset: 6

Within:

PCRE:

Special Options:

source