Vulnerabilities > CVE-2002-0364 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Web Servers |
NASL id | IIS_HTR_OVERFLOW.NASL |
description | The remote server is vulnerable to a buffer overflow in the .HTR filter. An attacker may use this flaw to execute arbitrary code on this host (although the exploitation of this flaw is considered difficult). |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11028 |
published | 2002-06-13 |
reporter | This script is Copyright (C) 2002-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11028 |
title | Microsoft IIS .HTR Filter Multiple Overflows (MS02-028) |
code |
|
Oval
accepted 2007-05-23T15:05:33.163-04:00 class vulnerability contributors name Tiffany Bergeron organization The MITRE Corporation name Glenn Strickland organization Secure Elements, Inc.
description Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise." family windows id oval:org.mitre.oval:def:182 status accepted submitted 2004-01-14T12:00:00.000-04:00 title Windows NT IIS Heap Overrun in HTR Chunked Encoding version 28 accepted 2011-05-16T04:02:39.320-04:00 class vulnerability contributors name Tiffany Bergeron organization The MITRE Corporation name Glenn Strickland organization Secure Elements, Inc. name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise." family windows id oval:org.mitre.oval:def:29 status accepted submitted 2004-01-14T12:00:00.000-04:00 title Windows 2000 IIS Heap Overrun in HTR Chunked Encoding version 33
Saint
bid | 4855 |
description | Microsoft IIS .HTR ISAPI chunked encoding buffer overflow |
id | web_server_iis_htr |
osvdb | 5316 |
title | iis_htr_isapi |
type | remote |
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html
- http://marc.info/?l=bugtraq&m=102392069305962&w=2
- http://marc.info/?l=bugtraq&m=102392069305962&w=2
- http://marc.info/?l=ntbugtraq&m=102392308608100&w=2
- http://marc.info/?l=ntbugtraq&m=102392308608100&w=2
- http://online.securityfocus.com/archive/1/276767
- http://online.securityfocus.com/archive/1/276767
- http://www.iss.net/security_center/static/9327.php
- http://www.iss.net/security_center/static/9327.php
- http://www.kb.cert.org/vuls/id/313819
- http://www.kb.cert.org/vuls/id/313819
- http://www.securityfocus.com/bid/4855
- http://www.securityfocus.com/bid/4855
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29