Microsoft FrontPage Server Extensions SmartHTML Buffer Overflow Vulnerability
BID:5804
Info
Microsoft FrontPage Server Extensions SmartHTML Buffer Overflow Vulnerability
| Bugtraq ID: | 5804 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0692 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Discovery is credited to Maninder Bharadwaj of the Digital Defense Services part of Digital GlobalSoft Ltd.. |
| Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft FrontPage Server Extensions 2002 Microsoft FrontPage Server Extensions 2000 |
| Not Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Home SP1 |
Discussion
Microsoft FrontPage Server Extensions SmartHTML Buffer Overflow Vulnerability
A vulnerability has been reported in the SmartHTML (shtml) interpreter component of FrontPage Server Extensions. In FrontPage Server Extensions 2000, the vulnerability is only exploitable as a denial of service. It is possible to cause consumption of CPU due to an infinite loop condition. This may adversely affect the server ability to perform other functions. Remote attackers may exploit this vulnerability to execute arbitrary code on target hosts running FrontPage Server Extensions 2002. This is due to it being a buffer overflow condition.
A vulnerability has been reported in the SmartHTML (shtml) interpreter component of FrontPage Server Extensions. In FrontPage Server Extensions 2000, the vulnerability is only exploitable as a denial of service. It is possible to cause consumption of CPU due to an infinite loop condition. This may adversely affect the server ability to perform other functions. Remote attackers may exploit this vulnerability to execute arbitrary code on target hosts running FrontPage Server Extensions 2002. This is due to it being a buffer overflow condition.
Exploit / POC
Microsoft FrontPage Server Extensions SmartHTML Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft FrontPage Server Extensions SmartHTML Buffer Overflow Vulnerability
Solution:
Microsoft has released patches addressing this issue.
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows XP Home
Microsoft FrontPage Server Extensions 2002
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows XP Home SP1
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Server SP3
Microsoft FrontPage Server Extensions 2000
Microsoft Windows 2000 Professional SP3
Microsoft Windows 2000 Server SP1
Microsoft Windows XP Professional
Microsoft Windows 2000 Professional SP2
Microsoft Windows XP Professional SP1
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Server
Solution:
Microsoft has released patches addressing this issue.
Microsoft Windows 2000 Professional
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows 2000 Server SP2
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows XP Home
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft FrontPage Server Extensions 2002
-
Microsoft Q329086
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q329086
Microsoft Windows 2000 Advanced Server SP1
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows XP Home SP1
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows 2000 Professional SP1
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows 2000 Server SP3
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft FrontPage Server Extensions 2000
-
Microsoft Q329085
Fix for FrontPage Server Extensions 2000 on Microsoft Windows 95/98/NT/2000/XP.
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q329085
Microsoft Windows 2000 Professional SP3
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows 2000 Server SP1
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows XP Professional
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows 2000 Professional SP2
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows XP Professional SP1
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows 2000 Advanced Server
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
Microsoft Windows 2000 Server
-
Microsoft Q324096
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324096
References
Microsoft FrontPage Server Extensions SmartHTML Buffer Overflow Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-053 (Microsoft)