This application requires Javascript for optimal performance.

MS.IIS.Chunked.Encoding.Heap.Buffer.Overflow

Release Date

Dec 24, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems

Description

This indicates an attack attempt to exploit a Buffer Overflow vulnerability in Microsoft Internet Information Services.

The vulnerability is due to insufficient sanitizing of user supplied inputs in the application. As a result, a remote attacker can exploit this to execute arbitrary code within the context of the application.

Affected Products

Microsoft IIS 5.0
Microsoft IIS 4.0

Recommended Actions

Refer to the vendor's website for suggested workaround.
http://technet.microsoft.com/en-us/security/bulletin/ms02-018

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2002-0079

Reference/s

http://technet.microsoft.com/en-us/security/bulletin/MS02-018.mspx (MS-ID)
http://www.securityfocus.com/bid/4485 (BugTraq)

Reference: VID-30405