Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability
BID:1565
Info
Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability
| Bugtraq ID: | 1565 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 10 2000 12:00AM |
| Updated: | Aug 10 2000 12:00AM |
| Credit: | Discovered by Burt Abreu & Søren Skov of VBExplorer.com. |
| Vulnerable: |
Microsoft IIS 5.0 Microsoft IIS 4.0 alpha Microsoft IIS 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability
Due to an error in canonicalization affecting CGI scripts and ISAPI extensions, incorrect permissions may be set for a given file on a web server following a malformed HTTP request. This will allow a user to perform actions on CGI or ISAPI-mapped files, including reading or executing, which would normally be denied. This does not apply to files in virtual folders.The correct file is located, but is concluded to be in a location different from its actual folder. Depending on the exact nature of the malformed URL, the file may inherit the permissions of any parent folder in the file's path.
Due to an error in canonicalization affecting CGI scripts and ISAPI extensions, incorrect permissions may be set for a given file on a web server following a malformed HTTP request. This will allow a user to perform actions on CGI or ISAPI-mapped files, including reading or executing, which would normally be denied. This does not apply to files in virtual folders.The correct file is located, but is concluded to be in a location different from its actual folder. Depending on the exact nature of the malformed URL, the file may inherit the permissions of any parent folder in the file's path.
Exploit / POC
Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability
Solution:
Microsoft has released the following patches which eliminate the vulnerability:
Microsoft IIS 4.0 alpha
Microsoft IIS 4.0
Microsoft IIS 5.0
Solution:
Microsoft has released the following patches which eliminate the vulnerability:
Microsoft IIS 4.0 alpha
-
Microsoft Q269862
http://download.microsoft.com/download/winntsp/Patch/q269862/NT4ALPHA/ EN-US/prmcan4a.exe -
Microsoft Q269862
http://download.microsoft.com/download/winntsp/Patch/q269862/NT4ALPHA/ EN-US/prmcan4as.exe
Microsoft IIS 4.0
-
Microsoft Q269862
http://download.microsoft.com/download/winntsp/Patch/q269862/NT4ALPHA/ EN-US/prmcan4i.exe -
Microsoft Q269862
http://download.microsoft.com/download/winntsp/Patch/q269862/NT4ALPHA/ EN-US/prmcan4is.exe
Microsoft IIS 5.0
References
Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability
References:
References: