PT-2005-3994 · Microsoft · Windows 2000
Published
2005-10-06
·
Updated
2008-09-05
·
CVE-2005-3172
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 versions prior to Update Rollup 1 for SP4
Description
The issue is related to the improper conversion of strings with Japanese composite characters by the WideCharToMultiByte function, potentially leading to data corruption or enabling buffer overflow attacks. This could occur when the composite character is in the last position of the string, preventing it from being null terminated.
Recommendations
For Microsoft Windows 2000 versions prior to Update Rollup 1 for SP4, apply Update Rollup 1 for SP4 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows 2000