RULE(RULE ID:1908979)

Rule General Information
Release Date: 2010-09-23
Rule Name: NETBIOS SMB-DS DCERPC Remote Activation bind attempt Vulnerability (CVE-2003-0528)
Severity:
CVE ID:
Rule Protection Details
Description: Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: MicrosoftSecurityBulletin:ms03-039
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0100.html
http://marc.info/?l=bugtraq&m=106407417011430&w=2
http://www.cert.org/advisories/CA-2003-23.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
* 使用防火墙阻塞至少下列端口: