First published: Mon Apr 22 2002(Updated: )
Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =4.0 | |
Microsoft Internet Information Services (IIS) | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0149 is rated as critical due to the potential for remote code execution and denial of service.
The best way to fix CVE-2002-0149 is to apply the latest security patches provided by Microsoft for Internet Information Services.
CVE-2002-0149 affects IIS versions 4.0, 5.0, and 5.1.
CVE-2002-0149 could be exploited by remote attackers using long file names to initiate buffer overflow attacks.
If you cannot patch, consider blocking unnecessary traffic to your IIS server and implementing strict access controls.