Vulnerabilities > CVE-2004-0193 - Unspecified vulnerability in ISS products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN iss
nessus
Summary
Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.
Vulnerable Configurations
Nessus
NASL family | Windows |
NASL id | BLACKICE_VERSION_CHECKER.NASL |
description | ISS BlackICE is a personal Firewall/IDS for windows Desktops. Several remote holes have been found in the product. An attacker, exploiting these flaws, would be able to either crash the remote firewall/IDS service or execute code on the target machine. According to the remote version number, the remote host is vulnerable to at least one remote overflow. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12114 |
published | 2004-03-19 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/12114 |
title | ISS BlackICE Multiple Remote Vulnerabilities |
code |
|
References
- http://marc.info/?l=bugtraq&m=107789851117176&w=2
- http://marc.info/?l=bugtraq&m=107789851117176&w=2
- http://secunia.com/advisories/10988
- http://secunia.com/advisories/10988
- http://www.eeye.com/html/Research/Advisories/AD20040226.html
- http://www.eeye.com/html/Research/Advisories/AD20040226.html
- http://www.eeye.com/html/Research/Upcoming/20040213.html
- http://www.eeye.com/html/Research/Upcoming/20040213.html
- http://www.kb.cert.org/vuls/id/150326
- http://www.kb.cert.org/vuls/id/150326
- http://www.osvdb.org/4072
- http://www.osvdb.org/4072
- http://www.securityfocus.com/bid/9752
- http://www.securityfocus.com/bid/9752
- http://xforce.iss.net/xforce/alerts/id/165
- http://xforce.iss.net/xforce/alerts/id/165
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15207
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15207