CVE-2008-3864: Input Validation
The ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allows remote attackers to cause a denial of service (service crash) via a packet with a large value in an unspecified size field.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3864?
CVE-2008-3864 is classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2008-3864?
To fix CVE-2008-3864, update your Trend Micro OfficeScan or Internet Security software to the latest version available.
What software is affected by CVE-2008-3864?
CVE-2008-3864 affects Trend Micro OfficeScan 8.0 SP1 Patch 1 and Trend Micro Internet Security 2007 and 2008.
What type of vulnerability is CVE-2008-3864?
CVE-2008-3864 is a denial of service vulnerability that allows remote attackers to crash the firewall service.
Can I mitigate CVE-2008-3864 without an update?
While an update is highly recommended, some network traffic filtering techniques may provide temporary mitigation for CVE-2008-3864.