CVE-2026-66349
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-125
Lectura fuera de límites
Fecha de publicación:
30/07/2026
Última modificación:
31/07/2026
Descripción
*** Pendiente de traducción *** The MMS server connection handler contains a flaw in its processing of <br />
BER-encoded request data. When an MMS confirmed request PDU containing <br />
an extended BER tag is received over an established session, the decoder<br />
may advance its internal buffer incorrectly due to a missing bounds <br />
check. This results in a one byte heap out-of-bounds read and causes the<br />
MMS service process to terminate, leading to a denial-of-service <br />
condition.
Impacto
Puntuación base 4.0
6.90
Gravedad 4.0
MEDIA
Puntuación base 3.x
6.50
Gravedad 3.x
MEDIA



