CVE Database
/

CVE-2006-3942

Back to search

CVE-2006-3942

Published: Jul 31, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research; the vulnerability is not associated with a mailslot.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2006-3037
vdb-entry
x_refsource_VUPEN
SSRT061264
vendor-advisory
x_refsource_HP
19215
vdb-entry
x_refsource_BID
MS06-063
vendor-advisory
x_refsource_MS
1016606
vdb-entry
x_refsource_SECTRACK
21276
third-party-advisory
x_refsource_SECUNIA
1017035
vdb-entry
x_refsource_SECTRACK
HPSBST02161
vendor-advisory
x_refsource_HP
27644
vdb-entry
x_refsource_OSVDB
smb-malformed-pipe(27999)
vdb-entry
x_refsource_XF
oval:org.mitre.oval:def:428
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now