Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2003-0525

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2003-0525
Last Modified 10 Sep 2008 03:19:31
Published 27 Aug 2003 12:00:00
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2003-0525

Summary

The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.

Vulnerable Systems

Operating System

  • Microsoft Windows Nt 4.0


References

XF - winnt-file-management-dos (12701)

MS - MS03-029

ATSTAKE - A072303-1


Last Updated: 27 May 2016 10:37:56