PT-2002-1161 · Microsoft · Internet Information Server
Published
2002-04-22
·
Updated
2020-11-23
·
CVE-2002-0072
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Internet Information Server (IIS) versions 4.0 through 5.1
Description
The issue arises from the w3svc.dll ISAPI filter's failure to handle long URLs properly, leading to a denial of service when the URL parser encounters a null pointer. This results in a crash.
Recommendations
For IIS versions 4.0 through 5.1, consider restricting access to long URLs as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Information Server