Rule:

--
3469

--
Summary:
This event is generated when an attempt is made to exploit a known 
vulnerability in Ipswitch WhatsUp Gold.

--
Impact:
Denial of Service (DoS).

--
Detailed Information:
This event is generated when an attempt is made to compromise a host
running Ipswitch WhatsUp Gold.

Due to a programming error in some versions of Ipswitch WhatsUp Gold,
some error signals are not processed correctly and are handed directly
to the kernel on an affected host. This causes a fatal exception and
crashes the service.

--
Affected Systems:
	Ipswitch WhatsUp Gold 8.0.3 and prior

--
Attack Scenarios:
An attacker need only request a file named "prn" using one of many file
extensions to cause the error.

--
Ease of Attack:
Simple. Exploit software is not required.

--
False Positives:
None known.

--
False Negatives:
None known.

--
Corrective Action:
Ensure the system is using an up to date version of the software and has
had all vendor supplied patches applied.

Check the host logfiles and application logs for signs of compromise.

--
Contributors:
Sourcefire Research Team
Alex Kirk <akirk@sourcefire.com>
Nigel Houghton <nigel.houghton@sourcefire.com>

--
Additional References:

--
