PT-2002-1434 · Microsoft · Internet Explorer+2

Published

2002-06-15

·

Updated

2021-07-23

·

CVE-2002-0371

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer versions 5.1 through 6.0 Microsoft Proxy Server version 2.0 Microsoft ISA Server version 2000
Description A buffer overflow issue exists in the gopher client, allowing remote attackers to execute arbitrary code via a gopher:// URL. This URL redirects the user to a real or simulated gopher server that sends a long response.
Recommendations For Microsoft Internet Explorer versions 5.1 through 6.0, apply the necessary patch to fix the buffer overflow issue in the gopher client. For Microsoft Proxy Server version 2.0, restrict access to gopher:// URLs to minimize the risk of exploitation. For Microsoft ISA Server version 2000, consider disabling the gopher client functionality until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0371

Affected Products

Isa Server
Internet Explorer
Proxy Server