MEDIUM · 5.0

CVE-2002-0072

The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided,...

Vulnerability Description

The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service (crash) when the URL parser accesses a null pointer.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
MicrosoftInternet Information Server4.0
MicrosoftInternet Information Services5.0

References

FAQ

What is CVE-2002-0072?

CVE-2002-0072 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided,...

How severe is CVE-2002-0072?

CVE-2002-0072 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-0072?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Internet Information Server, Microsoft Internet Information Services.