Microsoft ISA Server HTTP Request Smuggling Vulnerability
BID:13956
Info
Microsoft ISA Server HTTP Request Smuggling Vulnerability
| Bugtraq ID: | 13956 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1215 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Steve Orrin of Watchfire is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft ISA Server 2000 Enterprise Edition SP2 Microsoft ISA Server 2000 Enterprise Edition SP1 Microsoft ISA Server 2000 Enterprise Edition Microsoft ISA Server 2000 SP2 Microsoft ISA Server 2000 SP1 Microsoft ISA Server 2000 FP1 Microsoft ISA Server 2000 |
| Not Vulnerable: |
Microsoft ISA Server 2004 |
Discussion
Microsoft ISA Server HTTP Request Smuggling Vulnerability
Microsoft Internet Security and Acceleration (ISA) server is reported prone to a HTTP request smuggling attack.
The vendor reports that Microsoft ISA server fails to correctly handle an invalid HTTP request that contains multiple 'Content-Length' values in an invalid HTTP header.
A remote attacker may exploit this issue to launch cache poisoning or content-restriction bypass attacks against the affected server.
Microsoft Internet Security and Acceleration (ISA) server is reported prone to a HTTP request smuggling attack.
The vendor reports that Microsoft ISA server fails to correctly handle an invalid HTTP request that contains multiple 'Content-Length' values in an invalid HTTP header.
A remote attacker may exploit this issue to launch cache poisoning or content-restriction bypass attacks against the affected server.
Exploit / POC
Microsoft ISA Server HTTP Request Smuggling Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Microsoft ISA Server HTTP Request Smuggling Vulnerability
Solution:
Microsoft has released a fix to address this issue.
Microsoft ISA Server 2000 Enterprise Edition SP2
Microsoft ISA Server 2000 FP1
Microsoft ISA Server 2000 SP1
Microsoft ISA Server 2000
Microsoft ISA Server 2000 SP2
Solution:
Microsoft has released a fix to address this issue.
Microsoft ISA Server 2000 Enterprise Edition SP2
-
Microsoft Microsoft Internet Security and Acceleration (ISA) Server 2000 Cumulative Security Update
ISA Server Service Pack 2 must be installed prior to the installation of this update.
http://www.microsoft.com/downloads/details.aspx?familyid=E579813B-0372 -45BE-8070-3F4D7D4CB89C&displaylang=en
Microsoft ISA Server 2000 FP1
-
Microsoft Microsoft Internet Security and Acceleration (ISA) Server 2000 Cumulative Security Update
ISA Server Service Pack 2 must be installed prior to the installation of this update.
http://www.microsoft.com/downloads/details.aspx?familyid=E579813B-0372 -45BE-8070-3F4D7D4CB89C&displaylang=en
Microsoft ISA Server 2000 SP1
-
Microsoft Microsoft Internet Security and Acceleration (ISA) Server 2000 Cumulative Security Update
ISA Server Service Pack 2 must be installed prior to the installation of this update.
http://www.microsoft.com/downloads/details.aspx?familyid=E579813B-0372 -45BE-8070-3F4D7D4CB89C&displaylang=en
Microsoft ISA Server 2000
-
Microsoft Microsoft Internet Security and Acceleration (ISA) Server 2000 Cumulative Security Update
ISA Server Service Pack 2 must be installed prior to the installation of this update.
http://www.microsoft.com/downloads/details.aspx?familyid=E579813B-0372 -45BE-8070-3F4D7D4CB89C&displaylang=en
Microsoft ISA Server 2000 SP2
-
Microsoft Microsoft Internet Security and Acceleration (ISA) Server 2000 Cumulative Security Update
ISA Server Service Pack 2 must be installed prior to the installation of this update.
http://www.microsoft.com/downloads/details.aspx?familyid=E579813B-0372 -45BE-8070-3F4D7D4CB89C&displaylang=en
References
Microsoft ISA Server HTTP Request Smuggling Vulnerability
References:
References:
- Microsoft Security Bulletin MS05-034 (Microsoft)