CVE-2002-1052: Medium severity W3C Jigsaw vulnerability
Published Aug 31, 2002
·Updated
Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using the "con" device, or (2) obtain the physical path of the server using two requests to the "aux" device.
Affected Software
1 affected component
W3C Jigsaw=2.2.1
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Aug 31, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1052?
CVE-2002-1052 has been classified as a high severity vulnerability.
2
How do I fix CVE-2002-1052?
To fix CVE-2002-1052, upgrade W3C Jigsaw to version 2.2.1 or later.
3
What systems are affected by CVE-2002-1052?
CVE-2002-1052 specifically affects Jigsaw version 2.2.1 running on Windows systems.
4
What attacks can be performed using CVE-2002-1052?
CVE-2002-1052 allows remote attackers to execute denial of service attacks or reveal the physical path of the server.
5
Is CVE-2002-1052 still a threat today?
CVE-2002-1052 poses a threat primarily to older systems that have not been patched or upgraded.