CVE-2001-0336: Medium severity Microsoft Internet Information Server vulnerability
Published Jun 27, 2001
·Updated
The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.
Affected Software
1 affected component
Microsoft Internet Information Server<=5.0
Event History
Jun 27, 2001
CVE Published
04:00 AM
Sep 18, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0336?
CVE-2001-0336 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2001-0336?
To fix CVE-2001-0336, apply the appropriate patches provided by Microsoft for Internet Information Server 5.0 and earlier.
3
What type of attack does CVE-2001-0336 facilitate?
CVE-2001-0336 facilitates a denial of service attack through malformed requests sent to IIS 5.0.
4
Which versions of IIS are affected by CVE-2001-0336?
CVE-2001-0336 affects Microsoft Internet Information Server version 5.0 and earlier.
5
Is there a workaround for CVE-2001-0336?
Implementing network security measures, such as filtering requests, may mitigate the effects of CVE-2001-0336.