PT-2002-1161 · Microsoft · Internet Information Server

Published

2002-04-22

·

Updated

2020-11-23

·

CVE-2002-0072

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Internet Information Server (IIS) versions 4.0 through 5.1
Description The issue arises from the w3svc.dll ISAPI filter's failure to handle long URLs properly, leading to a denial of service when the URL parser encounters a null pointer. This results in a crash.
Recommendations For IIS versions 4.0 through 5.1, consider restricting access to long URLs as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0072

Affected Products

Internet Information Server