← Back

CVE-2006-3840

nvd nist
Published: Jul 27, 2006Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode.

Affected (11)

10 products
Blackice Pc Protection
Blackice Server Protection
Proventia Desktop
Realsecure Desktop
Realsecure Network
Realsecure Server Sensor
Proventia A Series Xpu
Proventia G Series Xpu
Proventia M Series Xpu
Proventia Server
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.6cpk
Version 3.6cpk
Iss
Version 8.0.675.1790
Version 8.0.812.1790
Version 7.0epk
Version 7.0
Version 7.0
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
Version 1.0.914.1880

Related CWEs

References (22)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.