Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A29
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A182
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-028
http://www.securityfocus.com/bid/4855
http://www.kb.cert.org/vuls/id/313819
http://www.iss.net/security_center/static/9327.php
http://online.securityfocus.com/archive/1/276767
http://marc.info/?l=ntbugtraq&m=102392308608100&w=2
http://marc.info/?l=bugtraq&m=102392069305962&w=2
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0099.html