For the past week or so, been getting frequent alerts for SPECIFIC-THREATS Eudora 250 command response buffer overflow.
The rule is:
flow:established, to_client
content:"250"
pcre:"/^250.*[^\x20-\x7E\t\x0D\x0A]/sm"
classtype:attempted-user
The alerts show that the messages which trigger the alert are flowing from my astaro box to my internal mail server which is not particularly helpful in finding the specific messages.
Is this alert saying that somebody is sending messages to one of my users with a version of Eudora that is missing a patch? Or is this a false positive that doesn't need to be worried about? Anybody else been getting any of these recently?
This thread was automatically locked due to age.