Security Advisory

CVE-2003-0525

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2003-07-25 04:00:00
Last updated 2024-08-08 01:58:10
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.