NT Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Fedora 17 released
· Chinese Windows 8 Release Preview (build 8400) leaked
· Daily Reviews Summary 05/29/12
· Microsoft Xbox 720 to feature in-game Skype integration
· Installing Lighttpd With PHP5 (PHP-FPM) And MySQL Support On Ubuntu 12.04
· CompatDB Updates 05/28/12
· Daily Reviews Summary 05/28/12
· GLSA 201205-04: Chromium, V8: Multiple vulnerabilities
· Daily Reviews Summary 05/26/12
· Microsoft Office for iPad reportedly on track for November release

Upcoming News
· Super Flower Golden Silent 500w Review - XSReviews
· eTeknix Insider Edition #15 @ eTeknix.com
· Ubuntu Weekly Newsletter Issue 267
· Cygnett GrooveTrip II Mini FM Transmitter Review @ TestFreaks
· The TR Podcast 112: By Kepler's beard, it's Trinity!
· Toshiba Excite 10 LE: The World's Thinnest 10" Tablet @ HotHardware.com
· CM Storm Trooper Gaming Case Review @ HardwareLOOK
· Binatone ReadMe Colour eReader @ HardwareLOOK
· Gainward GEFORCE GTX 680 2GB Phantom Video Card Review
· [CentOS-announce] CEBA-2012:0694 CentOS 6 lldpad Update

Windows Compatibility
· IObit Malware Fighter
· IObit SmartDefrag
· Realtek High Definition Audio for 2K/XP/03
· Advanced SystemCare with Antivirus 2012
· Samsung Drive Diagnostic Utility (Hutil)
· Google Chrome 18.0.1025.168 Final
· Skype
· Advanced SystemCare Free 5.3.0.245 Final
· IObit SmartDefrag v2 Beta 3.0
· Atheros Wireless AR5B91 Driver

New Forum Topics
· USB Not detected on any PC
by: AntNik45
on: 2012-05-09 18:37
0 replies, 0 views

· RESIDENT EVIL 2 for PC
by: elyp00
on: 2012-05-04 07:55
0 replies, 0 views

· Need to know if those graphic cards works well on Ubuntu
by: Dechiqtor
on: 2012-04-19 23:04
0 replies, 0 views

· Obtaining IE8
by: packman
on: 2012-04-14 19:46
0 replies, 0 views

· A few problems running Warcraft II Battle.net Edition on Vista
by: Lord Claremorris
on: 2012-04-08 16:15
0 replies, 0 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Windows XP
· Microsoft
· Updates
· Interviews
· Windows Server 2003
· General
· Windows Vista
· Webcasts
· Windows Server 2008
· Windows Home Server
· Windows 7
· Windows 8
· Windows Phone 7

What's New
Login to see an overview of all news stories since your last visit.

Affiliates

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

NT Compatible » News » June 2002 » Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise

Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise

Posted by Philipp Esselbach on: 06/13/2002 09:09 AM [ Print | 0 comment(s) ]

Microsoft has posted a secuity bulletin for the Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise issue




This patch eliminates a newly discovered vulnerability affecting Internet Information Services. Although Microsoft typically delivers cumulative patches for IIS, in this case we have delivered a patch that eliminates only this new vulnerability, while completing a cumulative patch. When the cumulative patch is customer-ready, we will update this bulletin with information on its availability. The FAQ provides information on the circumstances surrounding the vulnerability, and why we believe releasing a singleton patch immediately is in customers' best interests. To ensure that servers are fully protected against past as well as current vulnerabilities, we strongly recommend installing the previous cumulative patch (discussed in Microsoft Security Bulletin MS02-018) before
installing this patch.

The vulnerability is similar to the first vulnerability discussed in Microsoft Security Bulletin MS02-018. Like that vulnerability, this one involves a buffer overrun in the Chunked Encoding data transfer mechanism in IIS 4.0 and 5.0, and could likewise be used to overrun heap memory on the system, with the result of either causing the IIS service to fail or allowing code to be run on the server. The chief difference between the vulnerabilities is that the newly discovered one lies in the ISAPI extension that implements HTR - an older, largely obsolete scripting technology - where the previous one lay in the ISAPI extension that implements ASP.


Read more


Bookmark and Share

« Unchecked Buffer in Remote Access Service Phonebook Could Lead to Code Execution · WinTasks 4.0 Review »

NT Compatible » News » June 2002 » Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise
All products mentioned are registered trademarks or trademarks of their respective owners.
© 1998-2011 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition