Search

published date: August 27, 2003

CVE-2003-0525 : Denial of Service Vulnerability

Description

The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.

Product(s):

  • Microsoft Windows NT 4.0 Enterprise Server
  • Microsoft Windows NT 4.0 Server
  • Microsoft Windows NT 4.0 Terminal Server
  • Microsoft Windows 4.0 gold server
  • Microsoft Windows NT 4.0 Terminal Server Edition (Initial release)
  • Microsoft Windows NT 4.0 Service Pack 1 Enterprise Server

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2003-0525, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2003-0525 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?