Project

General

Profile

Actions

Bug #5786

closed
VJ PA

smb: possible evasion with trailing nbss data

Bug #5786: smb: possible evasion with trailing nbss data

Added by Victor Julien over 3 years ago. Updated almost 3 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

If nbss trailing data would be part of a larger read or write record, the streaming mode will likely get confused by the trailing data.


Subtasks 2 (0 open2 closed)

Bug #5898: smb: possible evasion with trailing nbss data (6.0.x backport)ClosedPhilippe AntoineActions
Bug #5904: smb: possible evasion with trailing nbss data (6.0.x backport)RejectedPhilippe AntoineActions

Related issues 1 (0 open1 closed)

Related to Suricata - Bug #5770: smb: no consistency check between NBSS length and length field for some SMB operationsClosedPhilippe AntoineActions

PA Updated by Philippe Antoine over 3 years ago Actions #1

  • Status changed from Assigned to In Review
  • Target version changed from TBD to 7.0.0-rc1

PA Updated by Philippe Antoine over 3 years ago Actions #2

  • Related to Bug #5770: smb: no consistency check between NBSS length and length field for some SMB operations added

PA Updated by Philippe Antoine about 3 years ago Actions #3

  • Target version changed from 7.0.0-rc1 to 7.0.0-rc2

PA Updated by Philippe Antoine about 3 years ago Actions #4

  • Status changed from In Review to Closed

Fixed by https://github.com/OISF/suricata/pull/8514

Would we want backports for this ?

VJ Updated by Victor Julien about 3 years ago Actions #5

  • Label Needs backport to 6.0 added

Yeah I think that would be good.

PA Updated by Philippe Antoine about 3 years ago Actions #6

  • Status changed from Closed to Resolved

PA Updated by Philippe Antoine about 3 years ago Actions #7

  • Subtask #5898 added

PA Updated by Philippe Antoine about 3 years ago Actions #8

Victor Julien wrote in #note-5:

Yeah I think that would be good.

Done ;-)

OT Updated by OISF Ticketbot about 3 years ago Actions #9

  • Subtask #5904 added

OT Updated by OISF Ticketbot about 3 years ago Actions #10

  • Label deleted (Needs backport to 6.0)

VJ Updated by Victor Julien about 3 years ago Actions #11

  • Status changed from Resolved to Closed

VJ Updated by Victor Julien about 3 years ago Actions #12

  • Private changed from Yes to No
Actions

Also available in: PDF Atom