Launch Printer Friendly Page Security TechCenter > Security Bulletins > Microsoft Security Bulletin MS02-026

Microsoft Security Bulletin MS02-026

Unchecked Buffer in ASP.NET Worker Process (Q322289)

Originally posted: June 06, 2002
Updated: February 28th, 2003

Summary

Who should read this bulletin:
Customers operating web servers running ASP.NET applications.

Impact of vulnerability:
Denial of Service, Potentially Run Code of Attacker's Choice.

Maximum Severity Rating:
Moderate

Recommendation:
Customers using StateServer mode should apply the patch. Customers who do not use StateServer mode need not take any action.

Affected Software:

  • Microsoft .NET Framework version 1.0, of which ASP.NET is a component.

General Information

Technical details

Frequently asked questions

Patch availability

Other information:

Support:

Security Resources: The Microsoft TechNet Security Web Site provides additional information about security in Microsoft products.

Disclaimer:

The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions:

  • V1.0 (June 06, 2002): Bulletin Created.
  • V2.0 (June 07, 2002): Bulletin updated to alert customers to manually install MS02-026 and make certain that VS.NET is closed when applying this patch.
  • V2.1 (February 28, 2003): Updated download links to Windows Update.