CVE-2009-0086 Information
Description
Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4 XP SP2 and SP3 Server 2003 SP1 and SP2 Vista Gold and SP1 and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response related to error handling aka \Windows HTTP Services Integer Underflow Vulnerability.\
Reference
http://osvdb.org/53620 http://secunia.com/advisories/34677 http://www.securityfocus.com/bid/34435 http://www.securitytracker.com/id?1022041 http://www.us-cert.gov/cas/techalerts/TA09-104A.html http://www.vupen.com/english/advisories/2009/1027 https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-013 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A6149
Share on: