存在问题:用多个ISS产品错误解析SMB信息能够导致堆溢出。这些ISS产品是检测网络攻击与入侵的程序的关键构成部分。 操作平台:RealSecure Network 7.0, XPU 20.15 through 22.9 Real Secure Server Sensor 7.0 XPU 20.16 through 22.9 Proventia A Series XPU 20.15 through 22.9 Proventia G Series XPU 22.3 through 22.9 Proventia M Series XPU 1.3 through 1.7 RealSecure Desktop 7.0 eba through ebh RealSecure Desktop 3.6 ebr through ecb RealSecure Guard 3.6 ebr through ecb RealSecure Sentry 3.6 ebr through ecb BlackICE PC Protection 3.6 cbr through ccb BlackICE Server Protection 3.6 cbr through ccb 漏洞危害:此堆溢出能够被潜在利用执行任意代码。 解决方案:厂商推荐升级软件。 漏洞评估:高危。不允许SMB链接的就不受此漏洞影响