IBM Security Bulletin: A vulnerability in Samba affects IBM Spectrum Scale SMB protocol access method (CVE-2017-7494)

A Samba vulnerability affects IBM Spectrum Scale SMB protocol access method which could allow a remote authenticated attacker to execute arbitrary code on the system, caused by improper access to named pipe endpoints. By uploading a specially-crafted shared library to a writeable share, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE(s): CVE-2017-7494

Affected product(s) and affected version(s):

IBM Spectrum Scale 4.2.3.0 – 4.2.3.1

IBM Spectrum Scale 4.2.2.0 – 4.2.2.3

IBM Spectrum Scale 4.2.1.0 – 4.2.1.2

IBM Spectrum Scale 4.2.0.0 – 4.2.0.4

IBM Spectrum Scale 4.1.1.0 – 4.1.1.14

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2ryQFpo
X-Force Database: http://ift.tt/2s4TkG5

The post IBM Security Bulletin: A vulnerability in Samba affects IBM Spectrum Scale SMB protocol access method (CVE-2017-7494) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2sjiM9u