Microsoft IIS Front Page Server Extension DoS Vulnerability
BID:2144
Info
Microsoft IIS Front Page Server Extension DoS Vulnerability
| Bugtraq ID: | 2144 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 22 2000 12:00AM |
| Updated: | Dec 22 2000 12:00AM |
| Credit: | Discovered by eEye Digital Security <http://www.eEye.com> and posted in a Microsoft Security Bulletin (MS00-100) on Dec 22, 2000. |
| Vulnerable: |
Microsoft IIS 5.0 Microsoft IIS 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS Front Page Server Extension DoS Vulnerability
Microsoft IIS ships with Front Page Server Extensions (FPSE) which enables administrators remote and local web page and content management. Browse - time support is another feature within FPSE which provides users with functional web applications.
Due to the way FPSE handles the processing of web forms, IIS is subject to a denial of service. By supplying malformed data to one of the FPSE functions IIS will stop responding. A restart of the service is required in order to gain normal functionality.
It should be noted that the victim only requires to have FPSE installed on the web server to be vulnerable.
Microsoft IIS ships with Front Page Server Extensions (FPSE) which enables administrators remote and local web page and content management. Browse - time support is another feature within FPSE which provides users with functional web applications.
Due to the way FPSE handles the processing of web forms, IIS is subject to a denial of service. By supplying malformed data to one of the FPSE functions IIS will stop responding. A restart of the service is required in order to gain normal functionality.
It should be noted that the victim only requires to have FPSE installed on the web server to be vulnerable.
Solution / Fix
Microsoft IIS Front Page Server Extension DoS Vulnerability
Solution:
Microsoft has released a patch which addresses this issue:
Microsoft IIS 4.0
Microsoft IIS 5.0
Solution:
Microsoft has released a patch which addresses this issue:
Microsoft IIS 4.0
-
Microsoft Q280322
http://download.microsoft.com/download/winntsrv40/Patch/q280322/NT4/EN -US/Q280322i.EXE
Microsoft IIS 5.0
References
Microsoft IIS Front Page Server Extension DoS Vulnerability
References:
References: