New Search

Windows 2000 ASN.1 Library Integer Overflow Vulnerabilities

oval:org.mitre.oval:def:653

Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL) as used in LSASS.EXE CRYPT32.DLL and other Microsoft executables and libraries on Windows NT 4.0 2000 and XP allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten or (2) modified bit strings.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows 2000
Class:
vulnerability
Reference(s):
  • CVE-2003-0818
Product(s):
  • Microsoft ASN.1 Library