Quotidien Shaarli

Tous les liens d'un jour sur une page.

May 5, 2023

A phantom has been haunting me: a deep dive into SMBGhost (part 1) - Raphaël Frisch
thumbnail

What is SMBGhost SMBGhost (CVE-2020-0796) is a vulnerability affecting SMB 3.1, and more precisely one of its decompression function. As SMB 3.1 added support for data compression in order to save bandwidth, it added a decompression function presenting an integer overflow resulting in multiple subsequent buffer overflows. Those buffer overflows are exploitable in a way […]