GHSA-rh3w-qc85-vjvvHighCVSS 6.5

The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an...

Published
July 31, 2026
Last Modified
July 31, 2026

🔗 CVE IDs covered (1)

📋 Description

The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.

🔗 References (4)