CVE-2002-1973: Buffer Overflow
Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1973?
CVE-2002-1973 is classified as a critical vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2002-1973?
To fix CVE-2002-1973, it is recommended to update the affected software to a version that has applied security patches.
What software is affected by CVE-2002-1973?
CVE-2002-1973 affects products utilizing Microsoft Foundation Class libraries, specifically BadBlue personal version 1.7.3.
Can CVE-2002-1973 be exploited remotely?
Yes, CVE-2002-1973 can be exploited by remote attackers to trigger the buffer overflow.
What impact does CVE-2002-1973 have on systems?
The main impact of CVE-2002-1973 is a denial of service that can lead to operational disruptions in affected systems.