Microsoft IIS 4 Redirect Remote Buffer Overflow Vulnerability
BID:10706
Info
Microsoft IIS 4 Redirect Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 10706 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0205 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | This vulnerability was disclosed by the vendor. |
| Vulnerable: |
Microsoft IIS 4.0 alpha Microsoft IIS 4.0 Avaya S8100 Media Servers 0 Avaya S3400 Message Application Server 0 Avaya IP600 Media Servers Avaya DefinityOne Media Servers |
| Not Vulnerable: | |
Discussion
Microsoft IIS 4 Redirect Remote Buffer Overflow Vulnerability
Microsoft IIS 4.0 is reported prone to a buffer overflow vulnerability when handling redirects.
It is reported that an attacker may exploit this vulnerability by issuing a large request to an affected IIS Web server. An attacker may exploit this issue to execute arbitrary code in the context of IIS. This could lead to complete compromise of an affected computer.
Microsoft IIS 4.0 is reported prone to a buffer overflow vulnerability when handling redirects.
It is reported that an attacker may exploit this vulnerability by issuing a large request to an affected IIS Web server. An attacker may exploit this issue to execute arbitrary code in the context of IIS. This could lead to complete compromise of an affected computer.
Exploit / POC
Microsoft IIS 4 Redirect Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft IIS 4 Redirect Remote Buffer Overflow Vulnerability
Solution:
Microsoft has released an updated security bulletin (MS04-021) and updates to address this issue for supported operating system versions. The updates listed in MS04-021 require that the updates listed in MS03-018 be installed as a perquisite. Please see the referenced advisories for further information.
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Avaya advise that customers follow the Microsoft recommendations to address this issue. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=197331&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft IIS 4.0
Solution:
Microsoft has released an updated security bulletin (MS04-021) and updates to address this issue for supported operating system versions. The updates listed in MS04-021 require that the updates listed in MS03-018 be installed as a perquisite. Please see the referenced advisories for further information.
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Avaya advise that customers follow the Microsoft recommendations to address this issue. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=197331&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft IIS 4.0
-
Microsoft Security Update for IIS 4.0 (KB841373)
This fix is for IIS running on Microsoft Windows NT 4.0 Service Pack 6a platforms.
http://download.microsoft.com/download/a/9/7/a9799893-a559-4ac1-bc88-f 9667b5954c4/Q841373I.exe
References
Microsoft IIS 4 Redirect Remote Buffer Overflow Vulnerability
References:
References:
- IIS may not respond after you install MS04-021 on an IIS 4.0 server (Microsoft)
- Internet Information Server 4 Baseline Security Checklist (Microsoft)
- Microsoft IIS Homepage (Microsoft)
- Microsoft Security Bulletin MS03-018 (Microsoft)
- Microsoft Security Bulletin MS04-021 (Microsoft)
- Technical Cyber Security Alert TA04-196A (CERT/CC)
- Vulnerability Note VU#717748 (CERT/CC)