First published: Wed Jan 21 2009(Updated: )
The ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allows remote attackers to cause a denial of service (service crash) via a packet with a large value in an unspecified size field.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Internet Security | ||
Trend Micro Internet Security | =17.0.1224 | |
Trend Micro OfficeScan XG | =8.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3864 is classified as a high severity vulnerability due to its potential to cause denial of service.
To fix CVE-2008-3864, update your Trend Micro OfficeScan or Internet Security software to the latest version available.
CVE-2008-3864 affects Trend Micro OfficeScan 8.0 SP1 Patch 1 and Trend Micro Internet Security 2007 and 2008.
CVE-2008-3864 is a denial of service vulnerability that allows remote attackers to crash the firewall service.
While an update is highly recommended, some network traffic filtering techniques may provide temporary mitigation for CVE-2008-3864.