PT-2004-1361 · Iss · Proventia A Series+6
Barnaby Jack
·
Published
2004-03-15
·
Updated
2017-10-10
·
CVE-2004-0193
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RealSecure Network versions 7.0
RealSecure Desktop versions 7.0 and 3.6
RealSecure Guard version 3.6
RealSecure Sentry version 3.6
Proventia A, G, and M Series (affected versions not specified)
BlackICE PC Protection version 3.6
BlackICE Server Protection version 3.6
Description
A heap-based buffer overflow issue exists in the ISS Protocol Analysis Module (PAM) used in certain products. This issue allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long
username.Recommendations
For RealSecure Network version 7.0, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module.
For RealSecure Desktop versions 7.0 and 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module.
For RealSecure Guard version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module.
For RealSecure Sentry version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module.
For Proventia A, G, and M Series, contact the vendor for guidance on updating to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module.
For BlackICE PC Protection version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module.
For BlackICE Server Protection version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blackice Pc Protection
Blackice Server Protection
Proventia A Series
Realsecure Desktop
Realsecure Guard
Realsecure Network
Realsecure Sentry