Project

General

Profile

Actions

Bug #5786

closed

smb: possible evasion with trailing nbss data

Added by Victor Julien almost 2 years ago. Updated over 1 year ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

If nbss trailing data would be part of a larger read or write record, the streaming mode will likely get confused by the trailing data.


Subtasks 2 (0 open2 closed)

Bug #5898: smb: possible evasion with trailing nbss data (6.0.x backport)ClosedPhilippe AntoineActions
Bug #5904: smb: possible evasion with trailing nbss data (6.0.x backport)RejectedPhilippe AntoineActions

Related issues 1 (0 open1 closed)

Related to Suricata - Bug #5770: smb: no consistency check between NBSS length and length field for some SMB operationsClosedPhilippe AntoineActions
Actions #1

Updated by Philippe Antoine almost 2 years ago

  • Status changed from Assigned to In Review
  • Target version changed from TBD to 7.0.0-rc1
Actions #2

Updated by Philippe Antoine almost 2 years ago

  • Related to Bug #5770: smb: no consistency check between NBSS length and length field for some SMB operations added
Actions #3

Updated by Philippe Antoine almost 2 years ago

  • Target version changed from 7.0.0-rc1 to 7.0.0-rc2
Actions #4

Updated by Philippe Antoine almost 2 years ago

  • Status changed from In Review to Closed

Fixed by https://github.com/OISF/suricata/pull/8514

Would we want backports for this ?

Actions #5

Updated by Victor Julien almost 2 years ago

  • Label Needs backport to 6.0 added

Yeah I think that would be good.

Actions #6

Updated by Philippe Antoine almost 2 years ago

  • Status changed from Closed to Resolved
Actions #7

Updated by Philippe Antoine almost 2 years ago

  • Subtask #5898 added
Actions #8

Updated by Philippe Antoine almost 2 years ago

Victor Julien wrote in #note-5:

Yeah I think that would be good.

Done ;-)

Actions #9

Updated by OISF Ticketbot almost 2 years ago

  • Subtask #5904 added
Actions #10

Updated by OISF Ticketbot almost 2 years ago

  • Label deleted (Needs backport to 6.0)
Actions #11

Updated by Victor Julien over 1 year ago

  • Status changed from Resolved to Closed
Actions #12

Updated by Victor Julien over 1 year ago

  • Private changed from Yes to No
Actions

Also available in: Atom PDF