National Cyber-Alert System
Vulnerability Summary for CVE-2003-0822
Original release date:12/15/2003
Last revised:09/10/2008
Source:
US-CERT/NIST
Overview
Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.
Impact
CVSS Severity (version 2.0):
Impact Subscore:
6.4
Exploitability Subscore:
10.0
CVSS Version 2 Metrics:
Access Vector: Network exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type:Provides user account access, Allows partial confidentiality, integrity, and availability violation; Allows unauthorized disclosure of information; Allows disruption of service
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
US-CERT Vulnerability Note: VU#279156
Name: VU#279156
External Source: XF
Name: fpse-debug-bo(13674)
Type: Advisory; Patch Information
External Source: MS
Name: MS03-051
Type: Advisory; Patch Information
External Source: SECUNIA
Name: 10195
External Source: BUGTRAQ
Name: 20031112 Frontpage Extensions Remote Command Execution
Type: Advisory
External Source: NTBUGTRAQ
Name: 20031112 Frontpage Extensions Remote Command Execution
US Government Resource: oval:org.mitre.oval:def:743
Name: oval:org.mitre.oval:def:743
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:699
Name: oval:org.mitre.oval:def:699
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:367
Name: oval:org.mitre.oval:def:367
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:366
Name: oval:org.mitre.oval:def:366
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:364
Name: oval:org.mitre.oval:def:364
Type: Tool Signature