SMB: EducatedScholar SMB Remote Code Execution

This signatures can be used to detect anomalous behavior within the SMBv1 protocol.

Extended Description

Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.

Affected Products

Samba samba

References

BugTraq: 01908

Short Name
SMB:EXPLOIT:EDUCATEDSCHOLAR-RCE
Severity
Major
Recommended
False
Recommended Action
None
Category
SMB
Keywords
Code EducatedScholar Execution Remote SMB bid:01908
Release Date
05/16/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Occasionally
Vendors

Samba

Debian

Redhat

Canonical

Found a potential security threat?