Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html - | |
References | () http://marc.info/?l=bugtraq&m=102392069305962&w=2 - | |
References | () http://marc.info/?l=ntbugtraq&m=102392308608100&w=2 - | |
References | () http://online.securityfocus.com/archive/1/276767 - | |
References | () http://www.iss.net/security_center/static/9327.php - | |
References | () http://www.kb.cert.org/vuls/id/313819 - US Government Resource | |
References | () http://www.securityfocus.com/bid/4855 - | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29 - |
Information
Published : 2002-07-03 04:00
Updated : 2024-11-20 23:38
NVD link : CVE-2002-0364
Mitre link : CVE-2002-0364
CVE.ORG link : CVE-2002-0364
JSON object : View
Products Affected
microsoft
- internet_information_server
- internet_information_services
CWE