CVE-2002-1992: Buffer Overflow
Published Dec 31, 2002
·Updated
Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template file name or (2) a long HTTP header.
Affected Software
3 affected components
Macromedia ColdFusion
Macromedia ColdFusion
Macromedia Coldfusion Professional
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Jul 14, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1992?
CVE-2002-1992 has a medium severity level due to its potential for causing denial of service.
2
How do I fix CVE-2002-1992?
To fix CVE-2002-1992, update ColdFusion MX to the latest patch provided by Macromedia.
3
Which versions of ColdFusion are affected by CVE-2002-1992?
CVE-2002-1992 affects ColdFusion MX versions used with IIS 4 or 5.
4
Can CVE-2002-1992 be exploited remotely?
Yes, CVE-2002-1992 can be exploited remotely through a long template file name or HTTP header.
5
What is the impact of exploiting CVE-2002-1992?
Exploiting CVE-2002-1992 can lead to a denial of service condition in IIS.