CVE-2005-1935
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/06/2005
Last modified:
11/07/2017
Description
Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to overwrite previously freed memory, as demonstrated using a SPNEGO token with a constructed bit string during HTTP authentication, and a different vulnerability than CVE-2003-0818. NOTE: the researcher has claimed that MS:MS04-007 fixes this issue.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_2000:*:sp4:*:fr:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_2003_server:64-bit:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_2003_server:r2:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_nt:4.0:sp6:terminal_server:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:server:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:workstation:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_xp:*:gold:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_xp:*:sp1:64-bit:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page