RULE(RULE ID:1905427)

Rule General Information
Release Date: 2017-12-25
Rule Name: Samba SMB1 smb_request_done Use-After-Free Vulnerability (CVE-2017-14746)
Severity:
CVE ID:
Rule Protection Details
Description: Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
Impact: A use-after-free vulnerability can be exploited by an attacker in the vulnerable product. Successful exploit may cause some adverse consequences, such as crash of the product, execution of arbitrary code.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:101907
SecurityTrackerID:1039856
https://www.debian.org/security/2017/dsa-4043
https://www.samba.org/samba/security/CVE-2017-14746.html
Solutions
The vendor has released a fix(4.5.15, 4.6.11, 4.7.3). For more infomation, please visit:
https://www.samba.org/samba/security/CVE-2017-14746.html