The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS02-028: Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise (Q321599)
Time: 18:34 EST/23:34 GMT | News Source: ActiveWin.com | Posted By: Todd Richardson

This patch eliminates a newly discovered vulnerability affecting Internet Information Services. Although Microsoft typically delivers cumulative patches for IIS, in this case we have delivered a patch that eliminates only this new vulnerability, while completing a cumulative patch. When the cumulative patch is customer-ready, we will update this bulletin with information on its availability. The FAQ provides information on the circumstances surrounding the vulnerability, and why we believe releasing a singleton patch immediately is in customers’ best interests. To ensure that servers are fully protected against past as well as current vulnerabilities, we strongly recommend installing the previous cumulative patch (discussed in Microsoft Security Bulletin MS02-018) before installing this patch.

The vulnerability is similar to the first vulnerability discussed in Microsoft Security Bulletin MS02-018. Like that vulnerability, this one involves a buffer overrun in the Chunked Encoding data transfer mechanism in IIS 4.0 and 5.0, and could likewise be used to overrun heap memory on the system, with the result of either causing the IIS service to fail or allowing code to be run on the server. The chief difference between the vulnerabilities is that the newly discovered one lies in the ISAPI extension that implements HTR – an older, largely obsolete scripting technology – where the previous one lay in the ISAPI extension that implements ASP.

Write Comment
Return to News

  Displaying 526 through 530 of 530
Prev | First
  The time now is 8:28:51 AM ET.
Any comment problems? E-mail us
#526 By 4240821 (178.217.45.3) at 6/3/2025 2:02:54 AM
https://nsfw.su/v/15kcln4592n7.php
https://nsfw.su/v/odea60819ht6.php
https://nsfw.su/v/6zssj3siem6v.php
https://nsfw.su/v/qhpcep7jfukd.php
https://nsfw.su/v/6ya2ciga2upw.php
https://nsfw.su/v/wdqais8znbn2.php
https://nsfw.su/v/kyfftupud4yi.php
https://nsfw.su/v/opsmw45cz8tb.php
https://nsfw.su/v/3lhvpkzqvly3.php
https://nsfw.su/v/pj2cfdm83euo.php

#527 By 4240821 (178.217.45.3) at 6/3/2025 2:11:28 PM
https://nsfw.su/v/3zkj1q2lpwzb.php
https://nsfw.su/v/tp4tpyzzzdj8.php
https://nsfw.su/v/nno4eyiphqfn.php
https://nsfw.su/v/18ijoyemf8z3.php
https://nsfw.su/v/ybqlnrx2myea.php
https://nsfw.su/v/n0nf3tq14eud.php
https://nsfw.su/v/osqksqtv69hz.php
https://nsfw.su/v/u0ds8u8iq4ju.php
https://nsfw.su/v/ug8fm2r3rqar.php
https://nsfw.su/v/4m2flf6b103l.php

#528 By 4240821 (178.217.45.3) at 6/3/2025 11:22:03 PM
https://nsfw.su/v/qegwom79v4pu.php
https://nsfw.su/v/3kkb6tiveeny.php
https://nsfw.su/v/oth0aay953ce.php
https://nsfw.su/v/jp01x0k3gou9.php
https://nsfw.su/v/mio8btwdrmet.php
https://nsfw.su/v/ldhjw4pqb8e0.php
https://nsfw.su/v/kvd7tig0d71w.php
https://nsfw.su/v/q5wic0g8qjgy.php
https://nsfw.su/v/fkxv4lbxpotq.php
https://nsfw.su/v/m6ly2r7tkh4x.php

#529 By 4240821 (178.217.45.3) at 6/4/2025 8:51:42 PM
https://nsfw.su/v/guu1qplk6mvd.php
https://nsfw.su/v/6qjap7m1r8ui.php
https://nsfw.su/v/6i6x69ghqkog.php
https://nsfw.su/v/7mryeh693vlo.php
https://nsfw.su/v/5r1rpi753vb7.php
https://nsfw.su/v/guu1qplk6mvd.php
https://nsfw.su/v/bnd95dqq1v5o.php
https://nsfw.su/v/6pdghvbns96h.php
https://nsfw.su/v/12zeersw2ifb.php
https://nsfw.su/v/bk7k6s7565fm.php

#530 By 4240821 (178.217.45.3) at 6/5/2025 12:55:32 AM
https://nsfw.su/v/kpcdr07nhee9.php
https://nsfw.su/v/5vzwivf3bpwy.php
https://nsfw.su/v/cakwf0pptmke.php
https://nsfw.su/v/p1m4uv4rb7p3.php
https://nsfw.su/v/vizfoe95n20l.php
https://nsfw.su/v/w1aa1ppmun9k.php
https://nsfw.su/v/utd5yizeshkm.php
https://nsfw.su/v/6wl6dv6m44jl.php
https://nsfw.su/v/4ap7z7ck8afk.php
https://nsfw.su/v/4bfsaq7n2nzv.php

Write Comment
Return to News
  Displaying 526 through 530 of 530
Prev | First
  The time now is 8:28:51 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *