Microsoft IIS WebDAV 'Propfind' Server Restart Vulnerability
BID:2690
Info
Microsoft IIS WebDAV 'Propfind' Server Restart Vulnerability
| Bugtraq ID: | 2690 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2001 12:00AM |
| Updated: | May 06 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq on May 6, 2001 by Georgi Guninski <[email protected]>. |
| Vulnerable: |
Microsoft IIS 5.0 |
| Not Vulnerable: | |
Discussion
Microsoft IIS WebDAV 'Propfind' Server Restart Vulnerability
Microsoft IIS is subject to a remote restart and possibly a denial of service condition. WebDAV contains a flaw in the handling of certain malformed requests. Submitting a valid WebDAV request containing numerous ':' could cause a remote restart of the server. This vulnerability has been known to affect the server performance and could lead to a denial of service condition, however this has not been verified.
Microsoft IIS is subject to a remote restart and possibly a denial of service condition. WebDAV contains a flaw in the handling of certain malformed requests. Submitting a valid WebDAV request containing numerous ':' could cause a remote restart of the server. This vulnerability has been known to affect the server performance and could lead to a denial of service condition, however this has not been verified.
Exploit / POC
Microsoft IIS WebDAV 'Propfind' Server Restart Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft IIS WebDAV 'Propfind' Server Restart Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft IIS WebDAV 'Propfind' Server Restart Vulnerability
References:
References: