CVE-2006-3840 - CVE House
Back to Database
Status published Medium CVE-2006-3840

The SMB Mailslot parsing functionality in PAM in multiple ISS...

Vulnerability Description

The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3840

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

blackice pc protection, blackice server protection, proventia desktop, realsecure desktop, realsecure network, realsecure server sensor, proventia a series xpu, proventia g series xpu, proventia m series xpu, proventia server
Vulnerable Versions:
3.6cpk, 8.0.675.1790, 8.0.812.1790, 7.0epk, 7.0, 1.0.914.1880

Timeline

Official Publish: July 27th, 2006
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.