Vulnerability Description
Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Internet Information Server | 4.0 |
| Microsoft | Internet Information Services | 5.0 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html
- http://marc.info/?l=bugtraq&m=102392069305962&w=2
- http://marc.info/?l=ntbugtraq&m=102392308608100&w=2
- http://online.securityfocus.com/archive/1/276767
- http://www.iss.net/security_center/static/9327.php
- http://www.kb.cert.org/vuls/id/313819US Government Resource
- http://www.securityfocus.com/bid/4855
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-02
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html
- http://marc.info/?l=bugtraq&m=102392069305962&w=2
- http://marc.info/?l=ntbugtraq&m=102392308608100&w=2
- http://online.securityfocus.com/archive/1/276767
- http://www.iss.net/security_center/static/9327.php
FAQ
What is CVE-2002-0364?
CVE-2002-0364 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked En...
How severe is CVE-2002-0364?
CVE-2002-0364 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0364?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Internet Information Server, Microsoft Internet Information Services.