PT-2004-1361 · Iss · Proventia A Series+6

Barnaby Jack

·

Published

2004-03-15

·

Updated

2017-10-10

·

CVE-2004-0193

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RealSecure Network versions 7.0 RealSecure Desktop versions 7.0 and 3.6 RealSecure Guard version 3.6 RealSecure Sentry version 3.6 Proventia A, G, and M Series (affected versions not specified) BlackICE PC Protection version 3.6 BlackICE Server Protection version 3.6
Description A heap-based buffer overflow issue exists in the ISS Protocol Analysis Module (PAM) used in certain products. This issue allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.
Recommendations For RealSecure Network version 7.0, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For RealSecure Desktop versions 7.0 and 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For RealSecure Guard version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For RealSecure Sentry version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For Proventia A, G, and M Series, contact the vendor for guidance on updating to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For BlackICE PC Protection version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module. For BlackICE Server Protection version 3.6, update to a version that includes a fix for the heap-based buffer overflow issue in the ISS Protocol Analysis Module.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0193

Affected Products

Blackice Pc Protection
Blackice Server Protection
Proventia A Series
Realsecure Desktop
Realsecure Guard
Realsecure Network
Realsecure Sentry