First published: Fri Nov 29 2002(Updated: )
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 | |
Microsoft Data Access Components | =2.5 | |
Microsoft Data Access Components | =2.6 | |
Microsoft Data Access Components | =2.1 | |
Internet Explorer | =5.5-sp2 | |
Internet Explorer | =5.0.1 | |
Internet Explorer | =5.0.1-sp2 | |
Internet Explorer | =5.0.1-sp1 | |
Internet Explorer | =5.5 | |
Internet Explorer | =5.5-sp1 | |
Internet Explorer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1142 is considered a critical vulnerability due to its potential for remote code execution.
To mitigate CVE-2002-1142, users should upgrade to the latest versions of Microsoft Data Access Components and Internet Explorer.
CVE-2002-1142 affects Microsoft Data Access Components 2.1 to 2.6 and Internet Explorer versions 5.0.1 through 6.0.
Yes, CVE-2002-1142 can be exploited remotely by sending a malformed HTTP request to the vulnerable service.
CVE-2002-1142 is classified as a heap-based buffer overflow vulnerability.