HTTP: Chunk Length Overflow

This protocol anomaly triggers when an HTTP message that has a chunk length in a Transfer-Encoding; chunk request that is greater than 0x7fffffff. Apache servers 1.3 to 1.3.24 and 2.0 to 2.0.36 are vulnerable. Attackers can cause a denial of service (DoS) or execute arbitrary code on the server.

Extended Description

A buffer overflow in the HTR ISAPI extension has been reported for Microsoft IIS (Internet Information Services). This condition affects IIS 4.0, IIS 5.0 and may be effectively mitigated by disabling the extension. Exploitation of this vulnerability may result in a denial of service or allow for a remote attacker to execute arbitrary instructions on the victim host. A number of Cisco products are affected by this vulnerability, although this issue is not present in the Cisco products themselves.

Affected Products

Microsoft iis

Short Name
HTTP:OVERFLOW:CHUNK-LEN-OFLOW
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2002-0392 CVE-2012-3544 KB960803 MS09-013 bid:4474 bid:5033
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3568
False Positive
Rarely
Vendors

Cisco

Microsoft

CVSS Score

5.0

Found a potential security threat?