PT-2002-1434 · Microsoft · Internet Explorer+2
Publicado
2002-06-15
·
Atualizado
2021-07-23
·
CVE-2002-0371
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer versions 5.1 through 6.0
Microsoft Proxy Server version 2.0
Microsoft ISA Server version 2000
Description
A buffer overflow issue exists in the gopher client, allowing remote attackers to execute arbitrary code via a gopher:// URL. This URL redirects the user to a real or simulated gopher server that sends a long response.
Recommendations
For Microsoft Internet Explorer versions 5.1 through 6.0, apply the necessary patch to fix the buffer overflow issue in the gopher client.
For Microsoft Proxy Server version 2.0, restrict access to gopher:// URLs to minimize the risk of exploitation.
For Microsoft ISA Server version 2000, consider disabling the gopher client functionality until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Isa Server
Internet Explorer
Proxy Server