Microsoft Security Bulletin: MS02-028

Thanks to ahodes for the heads up :)

UPDATED: MS02-028 Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise

Title: Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise (Q321599)

Released: 12 June 2002

Revised: 01 July 2002 (version 2.0)

Software: Internet Information Server

Impact: Run Code of Attacker"s Choice

Max Risk: Critical

Bulletin: MS02-028

Reason for Revision:

====================

On June 12, 2002, Microsoft released the original version of this bulletin. On July 1, 2002, the bulletin was updated to revise the severity rating. Specifically, Microsoft has increased the severity rating of this issue to "critical ." The revision is in response to a significant change in the threat environment due to an increased focus on chunked encoding vulnerabilities in general, and the discovery of hostile code attempting to exploit similar vulnerabilities on other platforms. Customers who have already disabled HTR or applied this patch need not take any action. Customers who have not disabled HTR should do so as soon as possible. Alternately, customers who cannot disable HTR should apply the patch immediately.

View: MS02-028

Download locations for this patch:

Download: Microsoft IIS 4.0

Download: Microsoft IIS 5.0

Report a problem with article
Next Article

IntelliMouse Recall

Previous Article

25,000km long eBone to be sold