This application requires Javascript for optimal performance.

MS.SMB.Response.DoS

Release Date

Jan 19, 2010

Severity

medium

Impact

Denial of Service: Remote attackers can crash vulnerable systems.

Description

This indicates an attack attempt against a denial-of-service vulnerability in Samba client.

The vulnerability is caused by improper bounds checking of incoming SMB packets. It may allow remote attackers to execute arbitrary code by sending a specially crafted SMB request to an SMB client. Failed exploit attempts will likely cause the program to crash, resulting in a denial-of-service condition.

Affected Products

Microsoft Windows 7
Microsoft Windows Server 2008 R2

Recommended Actions

Currently we are not aware of any officially supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-3676

Reference/s

http://www.microsoft.com/technet/security/Bulletin/MS10-020.mspx (MS-ID)
http://www.vupen.com/english/advisories/2009/3216
http://www.microsoft.com/technet/security/advisory/977544.mspx
http://g-laurent.blogspot.com/2009/11/windows-7-server-2008r2-remote-kernel.html

Reference: VID-17942