Vulnerability Name: CVE-2004-0362 (CCN-15442) Assigned: 2004-03-18 Published: 2004-03-18 Updated: 2017-07-11 Summary: Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm. CVSS v3 Severity: 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-Other Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2004-0362 Source: BUGTRAQ Type: UNKNOWN20040318 EEYE: Internet Security Systems PAM ICQ Server Response Processing Vulnerability Source: CCN Type: BugTraq Mailing List, 2004-03-18 23:57:46EEYE: Internet Security Systems PAM ICQ Server Response Processing Vulnerability Source: CCN Type: SA11073ISS Multiple Products ICQ Server Response Processing Vulnerability Source: SECUNIA Type: UNKNOWN11073 Source: CCN Type: CIAC Information Bulletin O-104ICQ Parsing in ISS Products May Lead to Buffer Overflow Source: CIAC Type: UNKNOWNO-104 Source: CCN Type: eEye Digital Defense Security Advisory AD20040318Internet Security Systems PAM ICQ Server Response Processing Vulnerability Source: EEYE Type: UNKNOWNAD20040318 Source: CCN Type: eEye Digital Defense Upcoming Advisory EEYEB-20040308Internet Security Systems Source: CCN Type: Internet Security Systems Web siteDownload Center Source: CCN Type: US-CERT VU#947254Internet Security Systems Protocol Analysis Module (PAM) does not properly handle ICQ server response messages Source: CERT-VN Type: Patch, Third Party Advisory, US Government ResourceVU#947254 Source: OSVDB Type: UNKNOWN4355 Source: CCN Type: OSVDB ID: 4355ISS Multiple Products PAM Component ICQ Protocol Parsing Overflow Source: BID Type: Exploit, Patch, Vendor Advisory9913 Source: CCN Type: BID-9913Internet Security Systems Protocol Analysis Module ICQ Parsing Buffer Overflow Vulnerability Source: CCN Type: Internet Security Systems Security Alert, March 18, 2004Vulnerability in ICQ Parsing in ISS Products Source: ISS Type: Patch, Vendor Advisory20040318 Vulnerability in ICQ Parsing in ISS Products Source: XF Type: UNKNOWNpam-icq-parsing-bo(15442) Source: XF Type: UNKNOWNpam-icq-parsing-bo(15442) Source: XF Type: UNKNOWNwitty-worm-propagation(15543) Vulnerable Configuration: Configuration 1 :cpe:/a:iss:blackice_agent_server:3.6ebz:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_agent_server:3.6eca:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_agent_server:3.6ecb:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_agent_server:3.6ecc:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_agent_server:3.6ecd:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_agent_server:3.6ece:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_agent_server:3.6ecf:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_pc_protection:3.6cbz:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_pc_protection:3.6cca:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_pc_protection:3.6ccb:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_pc_protection:3.6ccc:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_pc_protection:3.6ccd:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_pc_protection:3.6cce:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_pc_protection:3.6ccf:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_server_protection:3.6cbz:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_server_protection:3.6cca:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_server_protection:3.6ccb:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_server_protection:3.6ccc:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_server_protection:3.6ccd:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_server_protection:3.6cce:*:*:*:*:*:*:* OR cpe:/a:iss:blackice_server_protection:3.6ccf:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:3.6ebz:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:3.6eca:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:3.6ecb:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:3.6ecd:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:3.6ece:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:3.6ecf:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:7.0eba:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:7.0ebf:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:7.0ebg:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:7.0ebh:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:7.0ebj:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:7.0ebk:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_desktop:7.0ebl:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_guard:3.6ebz:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_guard:3.6eca:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_guard:3.6ecb:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_guard:3.6ecc:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_guard:3.6ecd:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_guard:3.6ece:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_guard:3.6ecf:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_network_sensor:7.0:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_network_sensor:7.0:xpu_20.11:*:*:*:*:*:* OR cpe:/a:iss:realsecure_network_sensor:7.0:xpu_22.10:*:*:*:*:*:* OR cpe:/a:iss:realsecure_network_sensor:7.0:xpu_22.4:*:*:*:*:*:* OR cpe:/a:iss:realsecure_network_sensor:7.0:xpu_22.9:*:*:*:*:*:* OR cpe:/a:iss:realsecure_sentry:3.6ebz:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_sentry:3.6eca:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_sentry:3.6ecb:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_sentry:3.6ecc:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_sentry:3.6ecd:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_sentry:3.6ece:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_sentry:3.6ecf:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.0:*:windows:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.0.1:*:windows:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.0.1_win_sr1.1:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.5:*:windows:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.5:sr3.2:windows:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.5:sr3.3:windows:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.5_win_sr3.1:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.5_win_sr3.4:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.5_win_sr3.5:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.5_win_sr3.6:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.5_win_sr3.7:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.5_win_sr3.8:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.5_win_sr3.9:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:6.5_win_sr3.10:*:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:7.0:xpu22.1:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:7.0:xpu22.10:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:7.0:xpu22.11:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:7.0:xpu22.2:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:7.0:xpu22.3:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:7.0:xpu22.4:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:7.0:xpu22.5:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:7.0:xpu22.6:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:7.0:xpu22.7:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:7.0:xpu22.8:*:*:*:*:*:* OR cpe:/a:iss:realsecure_server_sensor:7.0:xpu22.9:*:*:*:*:*:* Configuration 2 :cpe:/h:iss:proventia_a_series_xpu:20.11:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_a_series_xpu:22.1:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_a_series_xpu:22.2:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_a_series_xpu:22.3:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_a_series_xpu:22.4:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_a_series_xpu:22.5:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_a_series_xpu:22.6:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_a_series_xpu:22.7:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_a_series_xpu:22.8:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_a_series_xpu:22.9:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_a_series_xpu:22.10:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_g_series_xpu:22.1:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_g_series_xpu:22.2:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_g_series_xpu:22.3:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_g_series_xpu:22.4:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_g_series_xpu:22.5:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_g_series_xpu:22.6:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_g_series_xpu:22.7:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_g_series_xpu:22.8:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_g_series_xpu:22.9:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_g_series_xpu:22.10:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_g_series_xpu:22.11:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_m_series_xpu:1.1:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_m_series_xpu:1.2:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_m_series_xpu:1.3:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_m_series_xpu:1.4:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_m_series_xpu:1.5:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_m_series_xpu:1.6:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_m_series_xpu:1.7:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_m_series_xpu:1.8:*:*:*:*:*:*:* OR cpe:/h:iss:proventia_m_series_xpu:1.9:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:ibm:iss_realsecure_server_sensor:6.5:sr_3.10:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_desktop:7.0:ebf:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_desktop:3.6:ebz:*:*:*:*:*:* OR cpe:/a:iss:realsecure_guard:3.6:ebz:*:*:*:*:*:* OR cpe:/a:iss:realsecure_sentry:3.6:ebz:*:*:*:*:*:* OR cpe:/a:iss:blackice_agent_for_server:3.6:ebz:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_network:7.0:xpu_22.4:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_network:7.0:xpu_22.10:*:*:*:*:*:* OR cpe:/a:ibm:iss_blackice_pc_protection:3.6:ccd:*:*:*:*:*:* OR cpe:/a:ibm:iss_blackice_pc_protection:3.6:ccf:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_network:7.0:xpu_22.1:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_network:7.0:xpu_22.2:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_network:7.0:xpu_22.3:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_network:7.0:xpu_22.5:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_network:7.0:xpu_22.6:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_network:7.0:xpu_22.7:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_network:7.0:xpu_22.8:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_network:7.0:xpu_22.9:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_server_sensor:6.5:sr_3.7:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_server_sensor:6.5:sr_3.6:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_server_sensor:6.5:sr_3.5:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_server_sensor:6.5:sr_3.4:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_server_sensor:6.5:sr_3.3:*:*:*:*:*:* OR cpe:/a:ibm:iss_realsecure_server_sensor:6.5:sr_3.2:*:*:*:*:*:* Denotes that component is vulnerable BACK
iss blackice agent server 3.6ebz
iss blackice agent server 3.6eca
iss blackice agent server 3.6ecb
iss blackice agent server 3.6ecc
iss blackice agent server 3.6ecd
iss blackice agent server 3.6ece
iss blackice agent server 3.6ecf
iss blackice pc protection 3.6cbz
iss blackice pc protection 3.6cca
iss blackice pc protection 3.6ccb
iss blackice pc protection 3.6ccc
iss blackice pc protection 3.6ccd
iss blackice pc protection 3.6cce
iss blackice pc protection 3.6ccf
iss blackice server protection 3.6cbz
iss blackice server protection 3.6cca
iss blackice server protection 3.6ccb
iss blackice server protection 3.6ccc
iss blackice server protection 3.6ccd
iss blackice server protection 3.6cce
iss blackice server protection 3.6ccf
iss realsecure desktop 3.6ebz
iss realsecure desktop 3.6eca
iss realsecure desktop 3.6ecb
iss realsecure desktop 3.6ecd
iss realsecure desktop 3.6ece
iss realsecure desktop 3.6ecf
iss realsecure desktop 7.0eba
iss realsecure desktop 7.0ebf
iss realsecure desktop 7.0ebg
iss realsecure desktop 7.0ebh
iss realsecure desktop 7.0ebj
iss realsecure desktop 7.0ebk
iss realsecure desktop 7.0ebl
iss realsecure guard 3.6ebz
iss realsecure guard 3.6eca
iss realsecure guard 3.6ecb
iss realsecure guard 3.6ecc
iss realsecure guard 3.6ecd
iss realsecure guard 3.6ece
iss realsecure guard 3.6ecf
iss realsecure network sensor 7.0
iss realsecure network sensor 7.0 xpu_20.11
iss realsecure network sensor 7.0 xpu_22.10
iss realsecure network sensor 7.0 xpu_22.4
iss realsecure network sensor 7.0 xpu_22.9
iss realsecure sentry 3.6ebz
iss realsecure sentry 3.6eca
iss realsecure sentry 3.6ecb
iss realsecure sentry 3.6ecc
iss realsecure sentry 3.6ecd
iss realsecure sentry 3.6ece
iss realsecure sentry 3.6ecf
iss realsecure server sensor 6.0
iss realsecure server sensor 6.0.1
iss realsecure server sensor 6.0.1_win_sr1.1
iss realsecure server sensor 6.5
iss realsecure server sensor 6.5 sr3.2
iss realsecure server sensor 6.5 sr3.3
iss realsecure server sensor 6.5_win_sr3.1
iss realsecure server sensor 6.5_win_sr3.4
iss realsecure server sensor 6.5_win_sr3.5
iss realsecure server sensor 6.5_win_sr3.6
iss realsecure server sensor 6.5_win_sr3.7
iss realsecure server sensor 6.5_win_sr3.8
iss realsecure server sensor 6.5_win_sr3.9
iss realsecure server sensor 6.5_win_sr3.10
iss realsecure server sensor 7.0 xpu22.1
iss realsecure server sensor 7.0 xpu22.10
iss realsecure server sensor 7.0 xpu22.11
iss realsecure server sensor 7.0 xpu22.2
iss realsecure server sensor 7.0 xpu22.3
iss realsecure server sensor 7.0 xpu22.4
iss realsecure server sensor 7.0 xpu22.5
iss realsecure server sensor 7.0 xpu22.6
iss realsecure server sensor 7.0 xpu22.7
iss realsecure server sensor 7.0 xpu22.8
iss realsecure server sensor 7.0 xpu22.9
iss proventia a series xpu 20.11
iss proventia a series xpu 22.1
iss proventia a series xpu 22.2
iss proventia a series xpu 22.3
iss proventia a series xpu 22.4
iss proventia a series xpu 22.5
iss proventia a series xpu 22.6
iss proventia a series xpu 22.7
iss proventia a series xpu 22.8
iss proventia a series xpu 22.9
iss proventia a series xpu 22.10
iss proventia g series xpu 22.1
iss proventia g series xpu 22.2
iss proventia g series xpu 22.3
iss proventia g series xpu 22.4
iss proventia g series xpu 22.5
iss proventia g series xpu 22.6
iss proventia g series xpu 22.7
iss proventia g series xpu 22.8
iss proventia g series xpu 22.9
iss proventia g series xpu 22.10
iss proventia g series xpu 22.11
iss proventia m series xpu 1.1
iss proventia m series xpu 1.2
iss proventia m series xpu 1.3
iss proventia m series xpu 1.4
iss proventia m series xpu 1.5
iss proventia m series xpu 1.6
iss proventia m series xpu 1.7
iss proventia m series xpu 1.8
iss proventia m series xpu 1.9
ibm iss realsecure server sensor 6.5 sr_3.10
ibm iss realsecure desktop 7.0 ebf
ibm iss realsecure desktop 3.6 ebz
iss realsecure guard 3.6 ebz
iss realsecure sentry 3.6 ebz
iss blackice agent for server 3.6 ebz
ibm iss realsecure network 7.0 xpu_22.4
ibm iss realsecure network 7.0 xpu_22.10
ibm iss blackice pc protection 3.6 ccd
ibm iss blackice pc protection 3.6 ccf
ibm iss realsecure network 7.0 xpu_22.1
ibm iss realsecure network 7.0 xpu_22.2
ibm iss realsecure network 7.0 xpu_22.3
ibm iss realsecure network 7.0 xpu_22.5
ibm iss realsecure network 7.0 xpu_22.6
ibm iss realsecure network 7.0 xpu_22.7
ibm iss realsecure network 7.0 xpu_22.8
ibm iss realsecure network 7.0 xpu_22.9
ibm iss realsecure server sensor 6.5 sr_3.7
ibm iss realsecure server sensor 6.5 sr_3.6
ibm iss realsecure server sensor 6.5 sr_3.5
ibm iss realsecure server sensor 6.5 sr_3.4
ibm iss realsecure server sensor 6.5 sr_3.3
ibm iss realsecure server sensor 6.5 sr_3.2