Tim Wojtulewicz of Corelight reports:
Adding to the POP3 hardening in 7.0.2, the parser now
simply discards too many pending commands, rather than
any attempting to process them. Further, invalid server
responses do not result in command completion anymore.
Processing out-of-order commands or finishing commands
based on invalid server responses could result in
inconsistent analyzer state, potentially triggering null
pointer references for crafted traffic.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center