Skip to main content

Microsoft Windows CryptoAPI Multiple Vulnerabilities( 14 October 2009 )

Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 4406 Views

RISK: Medium Risk

1. Null Truncation in X.509 Common Name Vulnerability

A spoofing vulnerability exists in the Microsoft Windows CryptoAPI component when parsing ASN.1 information from X.509 certificates. An attacker who successfully exploited this vulnerability could impersonate another user or system.

2. Integer Overflow in X.509 Object Identifiers Vulnerability

A spoofing vulnerability exists in the Microsoft Windows CryptoAPI component when parsing ASN.1 object identifiers from X.509 certificates. An attacker who successfully exploited this vulnerability could impersonate another user or system.