CVE-2002-0149: Buffer Overflow
Published Apr 22, 2002
·Updated
Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.
Affected Software
2 affected components
Microsoft Internet Information Server=4.0
Microsoft Internet Information Services=5.0
Event History
Apr 22, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0149?
CVE-2002-0149 is rated as critical due to the potential for remote code execution and denial of service.
2
How do I fix CVE-2002-0149?
The best way to fix CVE-2002-0149 is to apply the latest security patches provided by Microsoft for Internet Information Services.
3
Which versions of IIS are affected by CVE-2002-0149?
CVE-2002-0149 affects IIS versions 4.0, 5.0, and 5.1.
4
What types of attacks could exploit CVE-2002-0149?
CVE-2002-0149 could be exploited by remote attackers using long file names to initiate buffer overflow attacks.
5
What should I do if I cannot patch my system to fix CVE-2002-0149?
If you cannot patch, consider blocking unnecessary traffic to your IIS server and implementing strict access controls.