First published: Mon Apr 22 2002(Updated: )
The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services (IIS) | =5.0 | |
Microsoft Internet Information Services | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-0073 is classified as a denial of service vulnerability.
To fix CVE-2002-0073, it is recommended to apply the latest security patches provided by Microsoft for IIS 4.0, 5.0, and 5.1.
CVE-2002-0073 affects Microsoft Internet Information Server versions 4.0, 5.0, and 5.1.
Yes, CVE-2002-0073 can be exploited remotely by attackers who have established an FTP session.
The consequences of CVE-2002-0073 include a denial of service condition that can disrupt FTP services.