Intrusion Prevention

Samba.SMB1.message_push_string.Information.Disclosure

Description

This indicates an attack attempt to exploit an Information Disclosure vulnerability in Samba.
The vulnerability is caused by an error when the vulnerable software handles a specially crafted SMB request. A remote attacker may be able to exploit this to disclose memory information on the targeted system.

Affected Products

Samba Team Samba 3.6.0 to 4.5.14
Samba Team Samba 3.6.0 to 4.6.10
Samba Team Samba 3.6.0 to 4.7.2

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
https://www.samba.org/samba/security/CVE-2017-15275.html

CVE References

CVE-2017-15275