Update Protection against Samba NetDFS RPC Remote Code Execution Vulnerability
| Check Point Reference: | CPAI-2007-079 | |
| Date Published: | ||
| Severity: | ||
| Source: | FrSIRT/ADV-2007-1805 | |
| Industry Reference(s): | CVE-2007-2446 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Samba Team Samba 3.x, 3.0.25rc3 and prior | ||
| Vulnerability Description A buffer overflow vulnerability has been reported in Samba. Samba is an open-source implementation of the network services suite SMB/CIFS. Samba implements many protocols and services, including the vulnerable NetDFS Service component which can be accessed through a Remote Procedure Call (RPC) interface. An attacker may exploit the vulnerability to execute arbitrary code on a target system via a specially crafted RPC request. |
||
|
Update/Patch Available Apply patches: Samba |
|
|
Vulnerability Details The vulnerability is due to a boundary error in the Samba NetDFS RPC interface that fails to properly handle specially crafted RPC requests. A remote attacker can exploit this issue by specially crafting a malicious RPC request and sending it to an affected system. Successful exploitation may allow execution of arbitrary code on a target system. |
Protection Overview
By enabling this protection, SmartDefense will detect and block malformed RPC requests sent to the NetDFS RPC interface.
In order for the protection to be activated, update your VPN-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The Update released on July 16, 2007 includes the following protections:
MIT Kerberos Multiple Remote Code Execution Vulnerabilities (CPAI-2007-078)
Samba NetDFS RPC Remote Code Execution Vulnerability (CPAI-2007-079)
Security Best Practice: Blocking Skype (SBP-2007-07)