Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2003-0525
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2003-0525

Description:
The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/12701

OVAL
  http://oval.mitre.org/oval/definitions/data/oval319.html

MS
  http://www.microsoft.com/technet/security/bulletin/ms03-029.asp

ATSTAKE
  http://www.atstake.com/research/advisories/2003/a072303-1.txt


Return to the previous page.