Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability
BID:4853
Info
Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability
| Bugtraq ID: | 4853 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0620 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Vulnerability discovery credited to Next Generation Security Software. |
| Vulnerable: |
Microsoft Commerce Server 2002 Microsoft Commerce Server 2000 SP2 Microsoft Commerce Server 2000 SP1 Microsoft Commerce Server 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability
Microsoft Commerce Server is a web server products for building, deploying, and analyzing e-commerce sites.
A buffer overflow vulnerability exists in the Profile Service of Commerce Server. The flaw resides in the code that handles certain types of API (Application Programming Interface) calls. Exploitation of this vulnerability may lead to a denial of service attack against Commerce Server or execution of arbitrary code in the Local System security context.
Microsoft Commerce Server is a web server products for building, deploying, and analyzing e-commerce sites.
A buffer overflow vulnerability exists in the Profile Service of Commerce Server. The flaw resides in the code that handles certain types of API (Application Programming Interface) calls. Exploitation of this vulnerability may lead to a denial of service attack against Commerce Server or execution of arbitrary code in the Local System security context.