PT-2002-1161 · Microsoft · Internet Information Server

Publicado

2002-04-22

·

Atualizado

2020-11-23

·

CVE-2002-0072

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Internet Information Server (IIS) versions 4.0 through 5.1
Description The issue arises from the w3svc.dll ISAPI filter's failure to handle long URLs properly, leading to a denial of service when the URL parser encounters a null pointer. This results in a crash.
Recommendations For IIS versions 4.0 through 5.1, consider restricting access to long URLs as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0072

Produtos afetados

Internet Information Server