CVE-2004-0362 - CVE House
Back to Database
Status published High CVE-2004-0362

Multiple stack-based buffer overflows in the ICQ parsing routines of...

Vulnerability Description

Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0362

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

blackice agent server, blackice pc protection, blackice server protection, realsecure desktop, realsecure guard, realsecure network sensor, realsecure sentry, realsecure server sensor, proventia a series xpu, proventia g series xpu, proventia m series xpu
Vulnerable Versions:
3.6ebz, 3.6eca, 3.6ecb, 3.6ecc, 3.6ecd, 3.6ece, 3.6ecf, 3.6cbz, 3.6cca, 3.6ccb, 3.6ccc, 3.6ccd, 3.6cce, 3.6ccf, 7.0eba, 7.0ebf, 7.0ebg, 7.0ebh, 7.0ebj, 7.0ebk, 7.0ebl, 7.0, 6.0, 6.0.1, 6.0.1_win_sr1.1, 6.5, 6.5_win_sr3.1, 6.5_win_sr3.4, 6.5_win_sr3.5, 6.5_win_sr3.6, 6.5_win_sr3.7, 6.5_win_sr3.8, 6.5_win_sr3.9, 6.5_win_sr3.10, 20.11, 22.1, 22.2, 22.3, 22.4, 22.5, 22.6, 22.7, 22.8, 22.9, 22.10, 22.11, 1.1, 1.2, 1.3, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9

Timeline

Official Publish: March 23rd, 2004
Last Modified: August 8th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.