Total vulnerabilities in the database
The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode.
Software | From | Fixed in |
---|---|---|
iss / realsecure_server_sensor | 7.0 | 7.0.x |
iss / proventia_desktop | 8.0.675.1790 | 8.0.675.1790.x |
iss / blackice_server_protection | 3.6cpk | 3.6cpk.x |
iss / blackice_pc_protection | 3.6cpk | 3.6cpk.x |
iss / proventia_desktop | 8.0.812.1790 | 8.0.812.1790.x |
iss / realsecure_network | 7.0 | 7.0.x |
iss / realsecure_desktop | 7.0epk | 7.0epk.x |
iss / proventia_g_series_xpu | - | - |
iss / proventia_a_series_xpu | - | - |
iss / proventia_m_series_xpu | - | - |
iss / proventia_server | 1.0.914.1880 | 1.0.914.1880.x |