New Search

Windows Server 2003 ASN.1 Library Integer Overflow Vulnerabilities

oval:org.mitre.oval:def:799

Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL) as used in LSASS.EXE CRYPT32.DLL and other Microsoft executables and libraries on Windows NT 4.0 2000 and XP allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten or (2) modified bit strings.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2003
Class:
vulnerability
Reference(s):
  • CVE-2003-0818
Product(s):
  • Microsoft ASN.1 Library