PT-2004-1361 · Iss · Proventia A Series+6

Barnaby Jack

·

Publicado

2004-03-15

·

Atualizado

2017-10-10

·

CVE-2004-0193

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RealSecure Network versions 7.0 RealSecure Desktop versions 7.0 and 3.6 RealSecure Guard version 3.6 RealSecure Sentry version 3.6 Proventia A, G, and M Series (affected versions not specified) BlackICE PC Protection version 3.6 BlackICE Server Protection version 3.6
Description A heap-based buffer overflow issue exists in the ISS Protocol Analysis Module (PAM) used in certain products. This issue allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.
Recommendations For RealSecure Network version 7.0, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For RealSecure Desktop versions 7.0 and 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For RealSecure Guard version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For RealSecure Sentry version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For Proventia A, G, and M Series, contact the vendor for guidance on updating to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For BlackICE PC Protection version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For BlackICE Server Protection version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0193

Produtos afetados

Blackice Pc Protection
Blackice Server Protection
Proventia A Series
Realsecure Desktop
Realsecure Guard
Realsecure Network
Realsecure Sentry