CVE-2004-0193: Buffer Overflow
Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0193?
CVE-2004-0193 has a high severity due to the potential for remote code execution through heap-based buffer overflow.
How do I fix CVE-2004-0193?
To fix CVE-2004-0193, ensure you apply the latest security patches for the affected ISS products.
Which products are affected by CVE-2004-0193?
CVE-2004-0193 affects various versions of ISS RealSecure and BlackICE products, including 7.0 and 3.6.
What is the exploit type for CVE-2004-0193?
The exploit type for CVE-2004-0193 is a heap-based buffer overflow.
Can CVE-2004-0193 be exploited remotely?
Yes, CVE-2004-0193 can be exploited remotely, allowing attackers to execute arbitrary code.