Description
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
Affected products
- microsoft / data_access_components2.1 – 2.1
- microsoft / data_access_components2.5 – 2.5
- microsoft / data_access_components2.6 – 2.6
- microsoft / ie6.0 – 6.0
- microsoft / internet_explorer5.0.1 – 5.0.1
- microsoft / internet_explorer5.0.1 – 5.0.1
- microsoft / internet_explorer5.0.1 – 5.0.1
- microsoft / internet_explorer5.5 – 5.5
- microsoft / internet_explorer5.5 – 5.5
- microsoft / internet_explorer5.5 – 5.5
- microsoft / internet_explorer6.0 – 6.0
Exploits & proofs of concept
- exploit-dbMicrosoft IIS - MDAC 'msadcs.dll' RDS DataStub Content-Type Overflow (MS02-065) (Metasploit)by Metasploit
References
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2730
- MISChttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0082.html
- MISChttp://www.securityfocus.com/bid/6214
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/10669
- MISChttp://www.kb.cert.org/vuls/id/542081
- MISChttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-065
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3573
- VENDOR_ADVISORYhttp://www.cert.org/advisories/CA-2002-33.html
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/10659
- VENDOR_ADVISORYhttp://www.foundstone.com/knowledge/randd-advisories-display.html?id=337
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A294
Updated 14m ago · 8 sources