|
|

CVE Reference: CVE-2005-2120 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2005-2120 |
|
|
Description: Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call. |
|
|
CVE Status: Candidate |
|
|
References: ST 1015042 SREASON http://securityreason.com/securityalert/71 SAID Secunia Advisory: SA17166 Secunia Advisory: SA17172 Secunia Advisory: SA17223 OVAL http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1328 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1244 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1519 OSVDB 18830 MS http://www.microsoft.com/technet/security/bulletin/ms05-047.mspx EEYE http://www.eeye.com/html/research/advisories/AD20051011c.html CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf CERT-VN 214572 CERT http://www.us-cert.gov/cas/techalerts/TA05-284A.html BID 15065 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |