|
|
|
Vulnerability Note VU#216324Microsoft ASN.1 Library improperly decodes malformed ASN.1 length valuesOverviewThe Microsoft ASN.1 Library improperly decodes malformed ASN.1 length values which could allow an unauthenticated, remote attacker to execute arbitrary code with SYSTEM privileges.I. DescriptionAbstract Syntax Notation number One (ASN.1) is an international standard used to describe and transmit data packets between applications and across networks. There is a buffer overflow vulnerability in the Microsoft ASN.1 Library that could allow an unauthenticated, remote attacker to execute arbitrary code with SYSTEM privileges on the affected system.II. ImpactAn unauthenticated, remote attacker could execute arbitrary code with SYSTEM privileges.III. SolutionApply PatchApply the patch (828028) referenced in Microsoft Security Bulletin MS04-007.
References
This vulnerability was reported by eEye Digital Security. This document was written by Damon Morda.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||