CVE

Id
2967  
CVE No.
CVE-2001-0146  
Status
Candidate  
Description
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL"s.  
Phase
Modified (20050509)  
Votes
ACCEPT(4) Baker, Cole, Lawler, Ziese | NOOP(1) Christey | RECAST(1) Frech  
Comments
Frech> (SF-EXEC) | XF:iis-malformed-url-dos(6171) | XF:exchange-malformed-url-dos(6172) | Not only is this two applications, but it is fixed by two patches. | Quoting Microsoft: | Because the flaw occurs in two different code modules, one of which installs | as part of IIS 5.0 and both of which install as part of Exchange 2000, it is | important for Exchange 2000 administrators to install both the IIS and | Exchange patches below. | Also, in the description, avoid using an apostrophe on "URLs" when it is | simply plural and not possessive (aka the "grocer"s apostrophe"). | Christey> Consider adding BID:2440 | Christey> Consider adding BID:2441