Index Server Search Function Contains Unchecked Buffer New
A buffer overrun security vulnerability exists in Index Server 2.0 which if provided an overly long value for a particular search parameter may cause the service to fail.
Issue
Index Server 2.0 has an unchecked buffer in a function that processes search requests. If an overly long value is provided for a particular search parameter, it overruns the buffer. If the buffer is overrun with random data, it causes Index Service to fail. If it is overrun with carefully selected data, code of the attacker's choice can be made to run on the server in the Local System security context.
Affected Products
- Index Server 2.0
Download
Patch: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=29660
Further Details
Source: Microsoft Corporation
Reference: Microsoft Corporation
Updated: May 10, 2001
>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<
















