Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
BID:2441
Info
Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
| Bugtraq ID: | 2441 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-0146 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 01 2001 12:00AM |
| Updated: | Jul 11 2009 04:46AM |
| Credit: | Discovered by Kevin Kotas and posted in a Microsoft Security Bulletin (MS01-014) on March 1, 2001. |
| Vulnerable: |
Microsoft IIS 5.0 Microsoft Exchange Server 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
Microsoft Exchange is subject to a denial of service condition due to the handling of web client requests. If an authenticated user requests a specially crafted URL multiple times to the host running Exchange, the web based mail service could stop responding. A restart of the service is required in order to gain normal functionality. Update: Microsoft IIS 5.0 suffers from a similar issue.
Microsoft Exchange is subject to a denial of service condition due to the handling of web client requests. If an authenticated user requests a specially crafted URL multiple times to the host running Exchange, the web based mail service could stop responding. A restart of the service is required in order to gain normal functionality. Update: Microsoft IIS 5.0 suffers from a similar issue.
Exploit / POC
Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
Solution:
Microsoft has released a patch which rectifies this issue. Exchange administrators are recommended to install the IIS patch as well as the Exchange patch:
Microsoft Exchange Server 2000
Microsoft IIS 5.0
Solution:
Microsoft has released a patch which rectifies this issue. Exchange administrators are recommended to install the IIS patch as well as the Exchange patch:
Microsoft Exchange Server 2000
-
Microsoft Q287678
http://download.microsoft.com/download/exchangeentserver/Patch/06.00.5 4.4418/NT5/EN-US/Q287678engi386.EXE
Microsoft IIS 5.0