Executive brief
A security vulnerability exists in the Natural Language Service (NLS), a component used by various operating systems to handle multi-language support and character encoding. An attacker could exploit this flaw to disrupt system operations or potentially gain unauthorized access to the system. This could lead to a loss of data confidentiality and integrity or cause a complete service outage.
Technical details
The vulnerability is a classic buffer overflow within the Natural Language Service (NLS) component. While the specific vendor is not identified in the legacy record, NLS components are typically responsible for internationalization, locale settings, and character set conversions. The attack vector is network-based with low complexity and requires no prior authentication. Successful exploitation could allow an attacker to execute arbitrary code or cause a crash, leading to a compromise of confidentiality, integrity, and availability. This is a legacy vulnerability first reported in 1997.
Affected products
- Unknown Natural Language Service (NLS)
Timeline
- 1997-02-13: disclosed: Vulnerability first published in NVD database.