HIGH
Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to overwrite previously freed memory, as demonstrated using a SPNEGO token with a constructed bit string during HTTP authentication, and a different vulnerability than CVE-2003-0818
Published Jun 9, 2005
7.5
HIGHCVSS 2.0
EPSS 26.63%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.