CVE-2006-3942

The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research; the vulnerability is not associated with a mailslot.
References
Link Resource
http://blogs.technet.com/msrc/archive/2006/07/28/443837.aspx
http://secunia.com/advisories/21276 Vendor Advisory
http://securitytracker.com/id?1016606
http://securitytracker.com/id?1017035
http://www.coresecurity.com/common/showdoc.php?idx=562&idxseccion=10
http://www.osvdb.org/27644
http://www.securityfocus.com/archive/1/443287/100/200/threaded
http://www.securityfocus.com/archive/1/449179/100/0/threaded
http://www.securityfocus.com/archive/1/449179/100/0/threaded
http://www.securityfocus.com/bid/19215
http://www.vupen.com/english/advisories/2006/3037 Vendor Advisory
http://xforce.iss.net/xforce/alerts/id/231
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-063
https://exchange.xforce.ibmcloud.com/vulnerabilities/27999
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A428
http://blogs.technet.com/msrc/archive/2006/07/28/443837.aspx
http://secunia.com/advisories/21276 Vendor Advisory
http://securitytracker.com/id?1016606
http://securitytracker.com/id?1017035
http://www.coresecurity.com/common/showdoc.php?idx=562&idxseccion=10
http://www.osvdb.org/27644
http://www.securityfocus.com/archive/1/443287/100/200/threaded
http://www.securityfocus.com/archive/1/449179/100/0/threaded
http://www.securityfocus.com/archive/1/449179/100/0/threaded
http://www.securityfocus.com/bid/19215
http://www.vupen.com/english/advisories/2006/3037 Vendor Advisory
http://xforce.iss.net/xforce/alerts/id/231
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-063
https://exchange.xforce.ibmcloud.com/vulnerabilities/27999
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A428
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:64-bit:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:itanium:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*

History

21 Nov 2024, 00:14

Type Values Removed Values Added
References () http://blogs.technet.com/msrc/archive/2006/07/28/443837.aspx - () http://blogs.technet.com/msrc/archive/2006/07/28/443837.aspx -
References () http://secunia.com/advisories/21276 - Vendor Advisory () http://secunia.com/advisories/21276 - Vendor Advisory
References () http://securitytracker.com/id?1016606 - () http://securitytracker.com/id?1016606 -
References () http://securitytracker.com/id?1017035 - () http://securitytracker.com/id?1017035 -
References () http://www.coresecurity.com/common/showdoc.php?idx=562&idxseccion=10 - () http://www.coresecurity.com/common/showdoc.php?idx=562&idxseccion=10 -
References () http://www.osvdb.org/27644 - () http://www.osvdb.org/27644 -
References () http://www.securityfocus.com/archive/1/443287/100/200/threaded - () http://www.securityfocus.com/archive/1/443287/100/200/threaded -
References () http://www.securityfocus.com/archive/1/449179/100/0/threaded - () http://www.securityfocus.com/archive/1/449179/100/0/threaded -
References () http://www.securityfocus.com/bid/19215 - () http://www.securityfocus.com/bid/19215 -
References () http://www.vupen.com/english/advisories/2006/3037 - Vendor Advisory () http://www.vupen.com/english/advisories/2006/3037 - Vendor Advisory
References () http://xforce.iss.net/xforce/alerts/id/231 - () http://xforce.iss.net/xforce/alerts/id/231 -
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-063 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-063 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27999 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27999 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A428 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A428 -

Information

Published : 2006-07-31 23:04

Updated : 2024-11-21 00:14


NVD link : CVE-2006-3942

Mitre link : CVE-2006-3942

CVE.ORG link : CVE-2006-3942


JSON object : View

Products Affected

microsoft

  • windows_2000
  • windows_xp
  • windows_2003_server
CWE
CWE-20

Improper Input Validation