Microsoft IIS 3.0 .htr Missing Variable Denial of Service Vulnerability
BID:1476
Info
Microsoft IIS 3.0 .htr Missing Variable Denial of Service Vulnerability
| Bugtraq ID: | 1476 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 14 2000 12:00AM |
| Updated: | Jul 14 2000 12:00AM |
| Credit: | Details of this vulnerability were released in a Microsoft advisory, MS00-044 |
| Vulnerable: |
Microsoft IIS 5.0 Microsoft IIS 4.0 alpha Microsoft IIS 4.0 Microsoft IIS 3.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS 3.0 .htr Missing Variable Denial of Service Vulnerability
Microsoft IIS 3.0 shipped with a number of HTR scripts, one of which could be used to cause a Denial of Service against the hosting machine. Although these scripts were only distributed with IIS 3.0, they would be retained during upgrade to 4.0 or 5.0 and therefore these versions may be vulnerable if they were installed as an upgrade to 3.0. The vulnerable script is used to browse directories and normally expects a directory name as a variable. If a request with this variable blank is received, the script enters an infinite loop resulting in system resource exhaustion. No further details were made available by Microsoft.
Microsoft IIS 3.0 shipped with a number of HTR scripts, one of which could be used to cause a Denial of Service against the hosting machine. Although these scripts were only distributed with IIS 3.0, they would be retained during upgrade to 4.0 or 5.0 and therefore these versions may be vulnerable if they were installed as an upgrade to 3.0. The vulnerable script is used to browse directories and normally expects a directory name as a variable. If a request with this variable blank is received, the script enters an infinite loop resulting in system resource exhaustion. No further details were made available by Microsoft.
Exploit / POC
Solution / Fix
Microsoft IIS 3.0 .htr Missing Variable Denial of Service Vulnerability
Solution:
Microsoft has provided the following patches which address this issue:
Microsoft IIS 4.0 alpha
Microsoft IIS 4.0
Microsoft IIS 5.0
Solution:
Microsoft has provided the following patches which address this issue:
Microsoft IIS 4.0 alpha
-
Microsoft Q267559
http://download.microsoft.com/download/winntsp/Patch/q267559/NT4ALPHA/ EN-US/htrdos4a.exe -
Microsoft Q267559
http://download.microsoft.com/download/winntsp/Patch/q267559/NT4ALPHA/ EN-US/htrdos4as.exe
Microsoft IIS 4.0
-
Microsoft Q267559
http://download.microsoft.com/download/winntsp/Patch/q267559/NT4ALPHA/ EN-US/htrdos4i.exe -
Microsoft Q267559
http://download.microsoft.com/download/winntsp/Patch/q267559/NT4ALPHA/ EN-US/htrdos4is.exe
Microsoft IIS 5.0
References
Microsoft IIS 3.0 .htr Missing Variable Denial of Service Vulnerability
References:
References: