PT-2005-3994 · Microsoft · Windows 2000
Publicado
2005-10-06
·
Atualizado
2008-09-05
·
CVE-2005-3172
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 versions prior to Update Rollup 1 for SP4
Description
The issue is related to the improper conversion of strings with Japanese composite characters by the WideCharToMultiByte function, potentially leading to data corruption or enabling buffer overflow attacks. This could occur when the composite character is in the last position of the string, preventing it from being null terminated.
Recommendations
For Microsoft Windows 2000 versions prior to Update Rollup 1 for SP4, apply Update Rollup 1 for SP4 to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows 2000