First published: Tue Dec 31 2002(Updated: )
The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial of service (crash) via a wp-html-rend request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iPlanet Web Server | =enterprise_4.0 | |
iPlanet Web Server | =enterprise_4.1 | |
Netscape Enterprise Server | =3.0 | |
Netscape Enterprise Server | =3.1 | |
Netscape Enterprise Server | =3.2 | |
Netscape Enterprise Server | =3.3 | |
Netscape Enterprise Server | =3.4 | |
Netscape Enterprise Server | =3.5 | |
Netscape Enterprise Server | =3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1655 has a severity rating of moderate as it allows for a denial of service attack resulting in server crashes.
To fix CVE-2002-1655, it is recommended to upgrade to a patched version of Netscape Enterprise Server or iPlanet Web Server.
CVE-2002-1655 affects Netscape Enterprise Server versions 3.0 to 3.6 and iPlanet Web Server versions 4.0 to 4.1.
CVE-2002-1655 exploits the Web Publishing feature by sending a specially crafted wp-html-rend request that crashes the server.
While CVE-2002-1655 primarily affects outdated software, any unpatched instances of those servers still pose a security threat.