FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-026 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6535 | vdb entry third party advisory |