CVE
- Id
- 2967
- CVE No.
- CVE-2001-0146
- Status
- Candidate
- Description
- IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL"s.
- Phase
- Modified (20050509)
- Votes
- ACCEPT(4) Baker, Cole, Lawler, Ziese | NOOP(1) Christey | RECAST(1) Frech
- Comments
- Frech> (SF-EXEC) | XF:iis-malformed-url-dos(6171) | XF:exchange-malformed-url-dos(6172) | Not only is this two applications, but it is fixed by two patches. | Quoting Microsoft: | Because the flaw occurs in two different code modules, one of which installs | as part of IIS 5.0 and both of which install as part of Exchange 2000, it is | important for Exchange 2000 administrators to install both the IIS and | Exchange patches below. | Also, in the description, avoid using an apostrophe on "URLs" when it is | simply plural and not possessive (aka the "grocer"s apostrophe"). | Christey> Consider adding BID:2440 | Christey> Consider adding BID:2441