Microsoft IIS SSINC.DLL Server Side Includes Buffer Overflow Vulnerability
BID:7734
Info
Microsoft IIS SSINC.DLL Server Side Includes Buffer Overflow Vulnerability
| Bugtraq ID: | 7734 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0224 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to Ren Guang Yuan of NSFOCUS Security Team. |
| Vulnerable: |
Microsoft IIS 5.0 |
| Not Vulnerable: |
Microsoft IIS 6.0 Microsoft IIS 5.1 Microsoft IIS 4.0 |
Exploit / POC
Microsoft IIS SSINC.DLL Server Side Includes Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft IIS SSINC.DLL Server Side Includes Buffer Overflow Vulnerability
Solution:
The following patches are available:
There is a dependency associated with this patch. It requires the patch from Microsoft Security Bulletin MS02-050 to be installed. If this patch is installed and MS02-050 is not present, client side certificates will be rejected. This functionality can be restored by installing the MS02-050 patch.
Microsoft IIS 5.0
Solution:
The following patches are available:
There is a dependency associated with this patch. It requires the patch from Microsoft Security Bulletin MS02-050 to be installed. If this patch is installed and MS02-050 is not present, client side certificates will be rejected. This functionality can be restored by installing the MS02-050 patch.
Microsoft IIS 5.0
-
Microsoft Q811114
IIS 5.0 patch to be installed on systems running Windows 2000 Service Pack 2 or Service Pack 3.
http://microsoft.com/downloads/details.aspx?FamilyId=2F5D9852-4ADD-44F 8-8715-AC3D7D7D94BF&displaylang=en