CVE-2001-0337: Medium severity Microsoft Internet Information Server vulnerability
Published May 24, 2001
·Updated
The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.
Affected Software
1 affected component
Microsoft Internet Information Server<=5.0
Event History
May 24, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0337?
CVE-2001-0337 is classified as a denial of service vulnerability.
2
How does CVE-2001-0337 affect systems running IIS 5.0?
CVE-2001-0337 allows attackers to exploit a memory leak introduced by certain patches, resulting in service disruption.
3
What versions of Internet Information Server are affected by CVE-2001-0337?
CVE-2001-0337 affects Microsoft Internet Information Server versions up to and including 5.0.
4
How can I mitigate the impact of CVE-2001-0337?
To mitigate CVE-2001-0337, consider upgrading to a version of IIS that is not affected by the vulnerability.
5
What are common attack vectors for CVE-2001-0337?
Attackers can exploit CVE-2001-0337 through a series of crafted requests targeting the affected IIS server.