Microsoft .Net Framework Multiple Null Byte Injection Vulnerabilities
BID:24791
Info
Microsoft .Net Framework Multiple Null Byte Injection Vulnerabilities
| Bugtraq ID: | 24791 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0042 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2007 12:00AM |
| Updated: | May 08 2009 04:46PM |
| Credit: | Paul Craig of Security Assessment is credited with the discovery of these issues. |
| Vulnerable: |
Microsoft .NET Framework 2.0 Microsoft .NET Framework 1.1 SP1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.0 SP3 Microsoft .NET Framework 1.0 SP2 Microsoft .NET Framework 1.0 SP1 Microsoft .NET Framework 1.0 HP Storage Management Appliance 2.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Customer Interaction Express (CIE) User Interface 1.0.2 Avaya Customer Interaction Express (CIE) User Interface 1.0 Avaya Customer Interaction Express (CIE) Server 1.0 Avaya CIE 1.0.2 Avaya CIE 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft .Net Framework Multiple Null Byte Injection Vulnerabilities
Microsoft .NET Framework is prone to multiple NULL-byte injection vulnerabilities because it fails to adequately sanitize user-supplied data.
An attacker can exploit these issues to access sensitive information that may aid in further attacks; other attacks are also possible.
Microsoft .NET Framework is prone to multiple NULL-byte injection vulnerabilities because it fails to adequately sanitize user-supplied data.
An attacker can exploit these issues to access sensitive information that may aid in further attacks; other attacks are also possible.
Exploit / POC
Microsoft .Net Framework Multiple Null Byte Injection Vulnerabilities
An attacker can exploit this issue via a browser.
The following example URI request is available:
http://www.example.com/[path]/somescript.asp%00
An attacker can exploit this issue via a browser.
The following example URI request is available:
http://www.example.com/[path]/somescript.asp%00
Solution / Fix
Microsoft .Net Framework Multiple Null Byte Injection Vulnerabilities
Solution:
Microsoft has released security bulletin MS07-040 as well as updates to address this issue. Please see the references for details.
Microsoft .NET Framework 2.0
Microsoft .NET Framework 1.0 SP3
Microsoft .NET Framework 1.1 SP1
Solution:
Microsoft has released security bulletin MS07-040 as well as updates to address this issue. Please see the references for details.
Microsoft .NET Framework 2.0
-
Microsoft KB928365 - .NET Framework 2.0 SYSTEM.WEB.DLL and MSCOREE.DLL Security Update for Windows 2000, Windo
http://www.microsoft.com/downloads/details.aspx?FamilyId=BA3CEB78-8E1B -4C38-ADFD-E8BC95AE548D -
Microsoft KB929916 - .NET Framework 2.0 SYSTEM.WEB.DLL Security Update for Windows Vista
http://www.microsoft.com/downloads/details.aspx?FamilyId=CBC9F3CF-C3C3 -45C4-82E3-E11398BC2CD2
Microsoft .NET Framework 1.0 SP3
-
Microsoft KB928367 - .NET Framework 1.0 Service Pack 3 SYSTEM.WEB.DLL and MSCOREE.DLL Security Update for Wind
http://www.microsoft.com/downloads/details.aspx?FamilyId=91D7AFE4-069B -4CE8-976E-9A01345A8603 -
Microsoft KB930494 - .NET Framework 1.0 Service Pack 3 SYSTEM.WEB.DLL and MSCOREE.DLL Security Update for Wind
http://www.microsoft.com/downloads/details.aspx?FamilyId=829A2C5B-11EC -4ED7-91AB-6961034147BC
Microsoft .NET Framework 1.1 SP1
-
Microsoft KB928366 - .NET Framework 1.1 Service Pack 1 SYSTEM.WEB.DLL and MSCOREE.DLL Security Update for Wind
http://www.microsoft.com/downloads/details.aspx?FamilyId=281FB2CD-C715 -4F05-A01F-0455D2D9EBFB -
Microsoft KB929729 - .NET Framework 1.1 Service Pack 1 SYSTEM.WEB.DLL and MSCOREE.DLL Security Update for Wind
http://www.microsoft.com/downloads/details.aspx?FamilyId=7EEA368D-7B82 -4583-8537-30351718A4E9 -
Microsoft KB933854 - .NET Framework 1.1 Service Pack 1 SYSTEM.WEB.DLL and MSCOREE.DLL Security Update for Wind
http://www.microsoft.com/downloads/details.aspx?FamilyId=2495E656-1E0A -4B83-90DA-821E68067A71
References
Microsoft .Net Framework Multiple Null Byte Injection Vulnerabilities
References:
References:
- .Net Home (Microsoft)
- Zero Day! (Security-Assessment)
- Multiple .NET Null Byte Injection Vulnerabilities (Paul Craig)
- ASA-2007-300 MS07-040 Vulnerabilities in .NET Framework Could Allow Remote Code (Avaya)
- Microsoft Security Bulletin MS07-040 (Microsoft)