First published: Wed Jul 03 2002(Updated: )
Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =4.0 | |
Microsoft Internet Information Services (IIS) | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0364 is considered a critical vulnerability due to the potential for arbitrary code execution.
To fix CVE-2002-0364, upgrade to a more secure version of Internet Information Services, such as IIS 6.0 or later.
CVE-2002-0364 affects Microsoft Internet Information Server versions 4.0 and 5.0.
Yes, CVE-2002-0364 can be exploited remotely by attackers through specially crafted HTR requests.
Exploitation of CVE-2002-0364 can lead to a full compromise of the web server, allowing the attacker to execute malicious code.