Vulnerability CVE-2006-3840


Published: 2006-07-27   Modified: 2012-02-12

Description:
The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode.

Type:

CWE-399

(Resource Management Errors)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
ISS -> Blackice pc protection 
ISS -> Blackice server protection 
ISS -> Proventia desktop 
ISS -> Realsecure desktop 
ISS -> Realsecure network 
ISS -> Realsecure server sensor 
ISS -> Proventia a series xpu 
ISS -> Proventia g series xpu 
ISS -> Proventia m series xpu 
ISS -> Proventia server 

 References:
http://securitytracker.com/id?1016590
http://securitytracker.com/id?1016591
http://securitytracker.com/id?1016592
http://www.nsfocus.com/english/homepage/research/0607.htm
http://www.securityfocus.com/archive/1/441278/100/0/threaded
http://www.securityfocus.com/bid/19178
http://www.vupen.com/english/advisories/2006/2996
http://xforce.iss.net/xforce/alerts/id/230
https://exchange.xforce.ibmcloud.com/vulnerabilities/27965
https://iss.custhelp.com/cgi-bin/iss.cfg/php/enduser/std_adp.php?p_faqid=3630

Copyright 2024, cxsecurity.com

 

Back to Top