RULE(RULE ID:306646)

Rule General Information
Release Date: 2015-01-05
Rule Name: MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability -4 (CVE-2001-0500)
Severity:
CVE ID:
Rule Protection Details
Description: Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:MS01-033
SecurityFocusBID:2880
Solutions
Microsoft has released a patch MS01-033 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/bulletin/MS01-033.asp