The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode.
2006-07-27T11:04:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | iss | blackice_pc_protection | 3.6cpk | Yes |
Application | iss | blackice_server_protection | 3.6cpk | Yes |
Application | iss | proventia_desktop | 8.0.675.1790 | Yes |
Application | iss | proventia_desktop | 8.0.812.1790 | Yes |
Application | iss | realsecure_desktop | 7.0epk | Yes |
Application | iss | realsecure_network | 7.0 | Yes |
Application | iss | realsecure_server_sensor | 7.0 | Yes |
Hardware | iss | proventia_a_series_xpu | * | Yes |
Hardware | iss | proventia_g_series_xpu | * | Yes |
Hardware | iss | proventia_m_series_xpu | * | Yes |
Hardware | iss | proventia_server | 1.0.914.1880 | Yes |