The SMB Mailslot parsing functionality in PAM in multiple ISS...
Vulnerability Description
The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3840
Credits & Attribution
No credits recorded in the NVD database.
References
- https://iss.custhelp.com/cgi-bin/iss.cfg/php/enduser/std_adp.php?p_faqid=3630
- http://www.securityfocus.com/archive/1/441278/100/0/threaded
- http://www.nsfocus.com/english/homepage/research/0607.htm
- http://secunia.com/advisories/21219
- http://www.vupen.com/english/advisories/2006/2996
- http://securitytracker.com/id?1016592
- http://xforce.iss.net/xforce/alerts/id/230
- http://www.securityfocus.com/bid/19178
- http://securitytracker.com/id?1016590
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27965
- http://securitytracker.com/id?1016591
More from iss
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.