PT-2002-2166 · Microsoft · Iis
Published
2002-11-12
·
Updated
2020-11-23
·
CVE-2002-1182
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
IIS versions 5.0 through 5.1
Description:
The issue allows remote attackers to cause a denial of service, resulting in a crash, by sending malformed WebDAV requests. These requests cause a large amount of memory to be assigned.
Recommendations:
For IIS versions 5.0 through 5.1, consider restricting access to WebDAV requests until a fix is available. As a temporary workaround, limiting the amount of memory that can be assigned by WebDAV requests may help mitigate the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iis