Secunia Logo
 
CVE Reference: CVE-2006-3840
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-3840

Description:
The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/27965

ST
  1016592
  1016590
  1016591

SAID
  Secunia Advisory: SA21219

MISC
  http://www.nsfocus.com/english/homepage/research/0607.htm

ISS
  http://xforce.iss.net/xforce/alerts/id/230

CONFIRM

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/441278/100/0/threaded

BID
  19178


Return to the previous page.